cbcvebase.

Adobe Commerce B2B vulnerabilities

134 known vulnerabilities affecting adobe/commerce_b2b.

Total CVEs
134
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH52MEDIUM61LOW13

Vulnerabilities

Page 7 of 7
CVE-2025-27189P4MEDIUMCVSS 4.3fixed in 1.3.3v1.3.3+5 more2025-04-08
CVE-2025-27189 [MEDIUM] CWE-352 CVE-2025-27189: Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affect Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable application, which may disrupt service
nvd
CVE-2025-24429P4LOWCVSS 3.5fixed in 1.3.3v1.3.3+4 more2025-02-11
CVE-2025-24429 [LOW] CWE-284 CVE-2025-24429: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of
nvd
CVE-2026-48001P4LOWCVSS 3.7v1.3.3v1.3.3-p1+53 more2026-07-14
CVE-2026-48001 [LOW] CWE-200 CVE-2026-48001: Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited dis Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-24432P4LOWCVSS 3.7fixed in 1.3.3v1.3.3+4 more2025-02-11
CVE-2025-24432 [LOW] CWE-367 CVE-2025-24432: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypass
nvd
CVE-2025-24430P4LOWCVSS 3.7fixed in 1.3.3v1.3.3+4 more2025-02-11
CVE-2025-24430 [LOW] CWE-367 CVE-2025-24430: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypass
nvd
CVE-2026-34685P4LOWCVSS 3.4fixed in 1.3.3v1.3.3+50 more2026-05-12
CVE-2026-34685 [LOW] CWE-20 CVE-2026-34685: Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this i
nvd
CVE-2024-45120P4LOWCVSS 3.1v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45120 [LOW] CWE-367 CVE-2024-45120: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-o Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to alter a condition between the check and the use of a resource, having a low impact on integrity. Explo
nvd
CVE-2026-21295P4LOWCVSS 3.1fixed in 1.3.3v1.3.3+62 more2026-03-11
CVE-2026-21295 [LOW] CWE-601 CVE-2026-21295: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
nvd
CVE-2024-45135P4LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45135 [LOW] CWE-284 CVE-2024-45135: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require user interact
nvd
CVE-2025-49549P4LOWCVSS 2.7fixed in 1.3.3v1.3.3+4 more2025-06-25
CVE-2025-49549 [LOW] CWE-863 CVE-2025-49549: Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue does not r
nvd
CVE-2024-45149P4LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45149 [LOW] CWE-284 CVE-2024-45149: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not requir
nvd
CVE-2024-45134P4LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45134 [LOW] CWE-200 CVE-2024-45134: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Infor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of this issue does not require user i
nvd
CVE-2024-45133P4LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45133 [LOW] CWE-284 CVE-2024-45133: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Infor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of this issue does not require user i
nvd
CVE-2025-27192P4LOWCVSS 2.7fixed in 1.3.3v1.3.3+4 more2025-04-08
CVE-2025-27192 [LOW] CWE-522 CVE-2025-27192: Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affect Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential inf
nvd