cbcvebase.

Adobe Magento vulnerabilities

204 known vulnerabilities affecting adobe/magento.

Total CVEs
204
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL26HIGH65MEDIUM99LOW14

Vulnerabilities

Page 10 of 11
CVE-2024-39415P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39415 [MEDIUM] CWE-285 CVE-2024-39415: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2024-39419P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39419 [MEDIUM] CWE-285 CVE-2024-39419: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user inter
nvd
CVE-2024-39407P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39407 [MEDIUM] CWE-285 CVE-2024-39407: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user inter
nvd
CVE-2024-39405P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39405 [MEDIUM] CWE-285 CVE-2024-39405: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user inter
nvd
CVE-2024-39416P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39416 [MEDIUM] CWE-285 CVE-2024-39416: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improp Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user int
nvd
CVE-2025-49550P4MEDIUMCVSS 4.3fixed in 2.4.5v2.4.5+3 more2025-06-25
CVE-2025-49550 [MEDIUM] CWE-863 CVE-2025-49550: Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue requires user interact
nvd
CVE-2024-39409P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39409 [MEDIUM] CWE-352 CVE-2024-39409: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-S Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page
nvd
CVE-2024-39410P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39410 [MEDIUM] CWE-352 CVE-2024-39410: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-S Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page
nvd
CVE-2024-39408P4MEDIUMCVSS 4.3≤ 2.4.3v2.4.4+3 more2024-08-14
CVE-2024-39408 [MEDIUM] CWE-352 CVE-2024-39408: Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-S Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changeson behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page
nvd
CVE-2026-48001P4LOWCVSS 3.7v2.4.6v2.4.6-p1+37 more2026-07-14
CVE-2026-48001 [LOW] CWE-200 CVE-2026-48001: Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited dis Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-24429P4LOWCVSS 3.5fixed in 2.4.4v2.4.4+4 more2025-02-11
CVE-2025-24429 [LOW] CWE-284 CVE-2025-24429: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of
nvd
CVE-2020-9690P4MEDIUMCVSS 4.2v2.3.5-p1 and earlier, and 2.3.5-p1 and earlier versions2020-07-29
CVE-2020-9690 [MEDIUM] CWE-203 CVE-2020-9690: Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepanc Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
nvd
CVE-2025-24432P4LOWCVSS 3.7fixed in 2.4.4v2.4.4+4 more2025-02-11
CVE-2025-24432 [LOW] CWE-367 CVE-2025-24432: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypass
nvd
CVE-2025-24430P4LOWCVSS 3.7fixed in 2.4.4v2.4.4+4 more2025-02-11
CVE-2025-24430 [LOW] CWE-367 CVE-2025-24430: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affect Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypass
nvd
CVE-2026-34685P4LOWCVSS 3.4fixed in 2.4.6v2.4.6+35 more2026-05-12
CVE-2026-34685 [LOW] CWE-20 CVE-2026-34685: Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this i
nvd
CVE-2024-45120P4LOWCVSS 3.1v2.4.4v2.4.5+2 more2024-10-10
CVE-2024-45120 [LOW] CWE-367 CVE-2024-45120: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-o Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to alter a condition between the check and the use of a resource, having a low impact on integrity. Explo
nvd
CVE-2026-21295P4LOWCVSS 3.1fixed in 2.4.5v2.4.5+4 more2026-03-11
CVE-2026-21295 [LOW] CWE-601 CVE-2026-21295: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlie Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
nvd
CVE-2024-45135P4LOWCVSS 2.7v2.4.3v2.4.4+3 more2024-10-10
CVE-2024-45135 [LOW] CWE-284 CVE-2024-45135: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require user interact
nvd
CVE-2025-49549P4LOWCVSS 2.7fixed in 2.4.5v2.4.5+3 more2025-06-25
CVE-2025-49549 [LOW] CWE-863 CVE-2025-49549: Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue does not r
nvd
CVE-2023-29293P4LOWCVSS 2.7v2.4.4v2.4.5+1 more2023-06-15
CVE-2023-29293 [LOW] CWE-20 CVE-2023-29293: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An admin privileged attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not
nvd