Adobe Commerce vulnerabilities
198 known vulnerabilities affecting adobe/commerce.
Total CVEs
198
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
4
Severity breakdown
CRITICAL15HIGH67MEDIUM102LOW14
Vulnerabilities
Page 9 of 10
CVE-2026-21291P4MEDIUMCVSS 4.8fixed in 2.4.4v2.4.4+5 more2026-03-11
CVE-2026-21291 [MEDIUM] CWE-79 CVE-2026-21291: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user interaction in that a victim must b
nvd
CVE-2025-54266P4MEDIUMCVSS 4.8v2.4.4v2.4.5+4 more2025-10-14
CVE-2025-54266 [MEDIUM] CWE-79 CVE-2025-54266: Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlie
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse
nvd
CVE-2023-29294P4MEDIUMCVSS 4.3v2.3.7v2.4.0+6 more2023-06-15
CVE-2023-29294 [MEDIUM] CWE-840 CVE-2023-29294: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-29288P4MEDIUMCVSS 4.3v2.3.7v2.4.0+6 more2023-06-15
CVE-2023-29288 [MEDIUM] CWE-863 CVE-2023-29288: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A privileged attacker could leverage this vulnerability to modify a minor functionality of another user's data. Exploitation of this issue does not req
nvd
CVE-2023-29295P4MEDIUMCVSS 4.3v2.3.7v2.4.0+6 more2023-06-15
CVE-2023-29295 [MEDIUM] CWE-863 CVE-2023-29295: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interacti
nvd
CVE-2025-24436P4MEDIUMCVSS 4.3v2.4.4v2.4.5+3 more2025-02-11
CVE-2025-24436 [MEDIUM] CWE-863 CVE-2025-24436: Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affect
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view select information. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-34105P4MEDIUMCVSS 4.8v2.3.7v2.4.0+6 more2024-06-13
CVE-2024-34105 [MEDIUM] CWE-79 CVE-2024-34105: Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cro
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable f
nvd
CVE-2024-45127P4MEDIUMCVSS 4.8v2.3.7v2.4.0+7 more2024-10-10
CVE-2024-45127 [MEDIUM] CWE-79 CVE-2024-45127: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerab
nvd
CVE-2024-39404P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39404 [MEDIUM] CWE-285 CVE-2024-39404: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user inter
nvd
CVE-2024-39411P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39411 [MEDIUM] CWE-285 CVE-2024-39411: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2024-39413P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39413 [MEDIUM] CWE-285 CVE-2024-39413: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2024-39414P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39414 [MEDIUM] CWE-284 CVE-2024-39414: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2024-39417P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39417 [MEDIUM] CWE-285 CVE-2024-39417: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2024-39415P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39415 [MEDIUM] CWE-285 CVE-2024-39415: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2024-39419P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39419 [MEDIUM] CWE-285 CVE-2024-39419: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user inter
nvd
CVE-2024-39407P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39407 [MEDIUM] CWE-285 CVE-2024-39407: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user inter
nvd
CVE-2024-39405P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39405 [MEDIUM] CWE-285 CVE-2024-39405: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user inter
nvd
CVE-2024-39416P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39416 [MEDIUM] CWE-285 CVE-2024-39416: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2025-49550P4MEDIUMCVSS 4.3fixed in 2.4.4v2.4.4+4 more2025-06-25
CVE-2025-49550 [MEDIUM] CWE-863 CVE-2025-49550: Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue requires user interact
nvd
CVE-2024-20716P4MEDIUMCVSS 4.9v2.4.4v2.4.5+1 more2024-02-15
CVE-2024-20716 [MEDIUM] CWE-400 CVE-2024-20716: Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Res
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to exhaust system resources, causing the application to slow down or crash. Exploitation of this issue do
nvd