Adobe Magento Commerce vulnerabilities

85 known vulnerabilities affecting adobe/magento_commerce.

Total CVEs
85
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH25MEDIUM44LOW4

Vulnerabilities

Page 1 of 5
CVE-2023-38208CRITICALCVSS 9.1≤ 2.4.4-p42023-08-09
CVE-2023-38208 [CRITICAL] CWE-78 Validate Your Inputs | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) Validate Your Inputs | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabilit
cvelistv5
CVE-2023-38209MEDIUMCVSS 6.5≤ 2.4.4-p42023-08-09
CVE-2023-38209 [MEDIUM] CWE-863 CVE-2023-38209: Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) ar Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerability that could lead to a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-29297CRITICALCVSS 9.1≥ unspecified, ≤ 2.4.6≥ unspecified, ≤ 2.4.5-p2+2 more2023-06-15
CVE-2023-29297 [CRITICAL] CWE-1336 Admin-to-admin stored XSS via cache poisoning Admin-to-admin stored XSS via cache poisoning Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could lead to arbitrary code execution by an admin-privilege authenticated attacker. Exploitation of this issue does not require user interaction.
cvelistv5
CVE-2023-22248HIGHCVSS 7.5≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-22248 [HIGH] CWE-863 CVE-2023-22248: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to leak another user's data. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-29292MEDIUMCVSS 4.9≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29292 [MEDIUM] CWE-918 CVE-2023-29292: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation o
cvelistv5nvd
CVE-2023-29289MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29289 [MEDIUM] CWE-91 CVE-2023-29289: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an XML Injection vulnerability. An attacker with low privileges can trigger a specially crafted script to a security feature bypass. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-29290MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29290 [MEDIUM] CWE-353 CVE-2023-29290: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-29287MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29287 [MEDIUM] CWE-200 CVE-2023-29287: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability that could lead to a security feature bypass. An attacker could leverage this vulnerability to leak minor user data. Exploitation of this issue does not require user interaction..
cvelistv5nvd
CVE-2023-29296MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.5-p12023-06-15
CVE-2023-29296 [MEDIUM] CWE-863 CVE-2023-29296: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to modify a minor functionality of another user's data. Exploitation of this issue does not
cvelistv5nvd
CVE-2023-29295MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29295 [MEDIUM] CWE-863 CVE-2023-29295: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interacti
cvelistv5nvd
CVE-2023-29291MEDIUMCVSS 4.9≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29291 [MEDIUM] CWE-918 CVE-2023-29291: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation o
cvelistv5nvd
CVE-2023-29294MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29294 [MEDIUM] CWE-840 CVE-2023-29294: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-22247HIGHCVSS 7.5≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22247 [HIGH] CWE-91 CVE-2023-22247: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Inj Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-22249MEDIUMCVSS 4.8≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22249 [MEDIUM] CWE-79 CVE-2023-22249: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored C Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the v
cvelistv5nvd
CVE-2023-22251MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22251 [MEDIUM] CWE-863 CVE-2023-22251: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorre Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
cvelistv5nvd
CVE-2023-22250MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22250 [MEDIUM] CWE-284 CVE-2023-22250: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Imprope Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2022-35698MEDIUMCVSS 5.4≥ unspecified, ≤ 2.4.52022-10-14
CVE-2022-35698 [CRITICAL] CWE-79 CVE-2022-35698: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cros Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
cvelistv5nvd
CVE-2022-35689MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.52022-10-14
CVE-2022-35689 [MEDIUM] CWE-284 CVE-2022-35689: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper A Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2022-35692MEDIUMCVSS 5.3v2.3.7v2.4.3+2 more2022-08-19
CVE-2022-35692 [MEDIUM] CWE-863 CVE-2022-35692: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require
cvelistv5nvd
CVE-2022-34256CRITICALCVSS 9.8≥ unspecified, ≤ 2.4.42022-08-16
CVE-2022-34256 [HIGH] CWE-285 CVE-2022-34256: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
cvelistv5nvd
Adobe Magento Commerce vulnerabilities | cvebase