cbcvebase.

Adobe Commerce B2B vulnerabilities

134 known vulnerabilities affecting adobe/commerce_b2b.

Total CVEs
134
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH52MEDIUM61LOW13

Vulnerabilities

Page 6 of 7
CVE-2026-21285P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+62 more2026-03-11
CVE-2026-21285 [MEDIUM] CWE-863 CVE-2026-21285: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Explo
nvd
CVE-2024-45123P4MEDIUMCVSS 6.1v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45123 [MEDIUM] CWE-79 CVE-2024-45123: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflec Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-45130P4MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45130 [MEDIUM] CWE-284 CVE-2024-45130: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require us
nvd
CVE-2024-45129P4MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45129 [MEDIUM] CWE-284 CVE-2024-45129: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require user in
nvd
CVE-2024-45121P4MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45121 [MEDIUM] CWE-284 CVE-2024-45121: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require us
nvd
CVE-2025-24423P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+4 more2025-02-11
CVE-2025-24423 [MEDIUM] CWE-284 CVE-2025-24423: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to modify select data. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-34655P4MEDIUMCVSS 4.8fixed in 1.3.3v1.3.3+50 more2026-05-12
CVE-2026-34655 [MEDIUM] CWE-79 CVE-2026-34655: Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse t
nvd
CVE-2026-34658P4MEDIUMCVSS 4.8fixed in 1.3.3v1.3.3+50 more2026-05-12
CVE-2026-34658 [MEDIUM] CWE-79 CVE-2026-34658: Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse t
nvd
CVE-2025-24420P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+4 more2025-02-11
CVE-2025-24420 [MEDIUM] CWE-863 CVE-2025-24420: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-24419P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+4 more2025-02-11
CVE-2025-24419 [MEDIUM] CWE-863 CVE-2025-24419: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-45122P4MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45122 [MEDIUM] CWE-284 CVE-2024-45122: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not requ
nvd
CVE-2025-24421P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+4 more2025-02-11
CVE-2025-24421 [MEDIUM] CWE-863 CVE-2025-24421: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to read select data. Exploitation of this issue does not require user interaction
nvd
CVE-2024-45125P4MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45125 [MEDIUM] CWE-863 CVE-2024-45125: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to have a low impact on integrity. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-34656P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+50 more2026-05-12
CVE-2026-34656 [MEDIUM] CWE-285 CVE-2026-34656: Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires
nvd
CVE-2026-47999P4MEDIUMCVSS 4.8v1.3.3v1.3.3-p1+53 more2026-07-14
CVE-2026-47999 [MEDIUM] CWE-79 CVE-2026-47999: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-21291P4MEDIUMCVSS 4.8fixed in 1.3.3v1.3.3+62 more2026-03-11
CVE-2026-21291 [MEDIUM] CWE-79 CVE-2026-21291: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user interaction in that a victim must b
nvd
CVE-2025-24436P4MEDIUMCVSS 4.3v1.3.3v1.3.4+3 more2025-02-11
CVE-2025-24436 [MEDIUM] CWE-863 CVE-2025-24436: Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affect Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view select information. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-45127P4MEDIUMCVSS 4.8v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45127 [MEDIUM] CWE-79 CVE-2024-45127: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerab
nvd
CVE-2025-54266P4MEDIUMCVSS 4.8v1.3.3v1.3.4+4 more2025-10-14
CVE-2025-54266 [MEDIUM] CWE-79 CVE-2025-54266: Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlie Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse
nvd
CVE-2025-49550P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+4 more2025-06-25
CVE-2025-49550 [MEDIUM] CWE-863 CVE-2025-49550: Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue requires user interact
nvd