cbcvebase.

Adobe Commerce vulnerabilities

207 known vulnerabilities affecting adobe/commerce.

Total CVEs
207
CISA KEV
4
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH77MEDIUM100LOW14

Vulnerabilities

Page 7 of 11
CVE-2026-21310P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+67 more2026-03-11
CVE-2026-21310 [MEDIUM] CWE-20 CVE-2026-21310: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-48000P4MEDIUMCVSS 6.1v2.4.4v2.4.4-p1+74 more2026-07-14
CVE-2026-48000 [MEDIUM] CWE-601 CVE-2026-48000: Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result i Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed.
nvd
CVE-2022-34259P4MEDIUMCVSS 5.3≥ 2.3.0, < 2.3.7≥ 2.4.0, < 2.4.3+3 more2022-08-16
CVE-2022-34259 [MEDIUM] CWE-284 CVE-2022-34259: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user in
nvd
CVE-2024-34106P4MEDIUMCVSS 5.3v2.3.7v2.4.0+6 more2024-06-13
CVE-2024-34106 [MEDIUM] CWE-863 CVE-2024-34106: Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to gain unauthorized access or perform actions with the privileges of another user. Exploitation of this issue does not require u
nvd
CVE-2024-45128P4MEDIUMCVSS 5.4v2.3.7v2.4.0+7 more2024-10-10
CVE-2024-45128 [MEDIUM] CWE-863 CVE-2024-45128: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity and availability. Exploitation of this issue doe
nvd
CVE-2026-21294P4MEDIUMCVSS 5.5fixed in 2.4.4v2.4.4+67 more2026-03-11
CVE-2026-21294 [MEDIUM] CWE-918 CVE-2026-21294: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and bypass security controls. Exploitat
nvd
CVE-2025-27190P4MEDIUMCVSS 5.3v2.4.4v2.4.5+3 more2025-04-08
CVE-2025-27190 [MEDIUM] CWE-284 CVE-2025-27190: Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affect Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user int
nvd
CVE-2025-27191P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+4 more2025-04-08
CVE-2025-27191 [MEDIUM] CWE-284 CVE-2025-27191: Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affect Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user int
nvd
CVE-2025-27206P4MEDIUMCVSS 5.3v2.4.4v2.4.5+3 more2025-06-10
CVE-2025-27206 [MEDIUM] CWE-284 CVE-2025-27206: Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this issue does not require user interac
nvd
CVE-2022-35689P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+1 more2022-10-14
CVE-2022-35689 [MEDIUM] CWE-284 CVE-2022-35689: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper A Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-49559P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+4 more2025-08-12
CVE-2025-49559 [MEDIUM] CWE-22 CVE-2025-49559: Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlie Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify limited data. Exploitation of this
nvd
CVE-2024-39418P4MEDIUMCVSS 5.4≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39418 [MEDIUM] CWE-285 CVE-2024-39418: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures to view and edit low-sensitivity information. Exploitation of this issue does not re
nvd
CVE-2026-48371P4MEDIUMCVSS 5.4v2.4.4v2.4.4-p1+74 more2026-07-14
CVE-2026-48371 [MEDIUM] CWE-79 CVE-2026-48371: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2023-29290P4MEDIUMCVSS 5.3v2.3.7v2.4.0+6 more2023-06-15
CVE-2023-29290 [MEDIUM] CWE-353 CVE-2023-29290: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-45124P4MEDIUMCVSS 5.3v2.3.7v2.4.0+7 more2024-10-10
CVE-2024-45124 [MEDIUM] CWE-284 CVE-2024-45124: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require user interaction
nvd
CVE-2026-21282P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+67 more2026-03-11
CVE-2026-21282 [MEDIUM] CWE-20 CVE-2026-21282: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing limited impact to application availability. Exploi
nvd
CVE-2023-22250P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22250 [MEDIUM] CWE-284 CVE-2023-22250: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Imprope Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
nvd
CVE-2022-35692P4MEDIUMCVSS 5.3≥ 2.4.0, < 2.4.42022-08-19
CVE-2022-35692 [MEDIUM] CWE-863 CVE-2022-35692: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require
nvd
CVE-2023-29291P4MEDIUMCVSS 4.9v2.3.7v2.4.0+6 more2023-06-15
CVE-2023-29291 [MEDIUM] CWE-918 CVE-2023-29291: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation o
nvd
CVE-2023-29292P4MEDIUMCVSS 4.9v2.3.7v2.4.0+6 more2023-06-15
CVE-2023-29292 [MEDIUM] CWE-918 CVE-2023-29292: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation o
nvd
Adobe Commerce vulnerabilities | cvebase