cbcvebase.

Adobe Magento Commerce vulnerabilities

81 known vulnerabilities affecting adobe/magento_commerce.

Total CVEs
81
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH24MEDIUM44LOW4

Vulnerabilities

Page 4 of 5
CVE-2021-36026P4MEDIUMCVSS 6.1≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36026 [MEDIUM] CWE-79 CVE-2021-36026: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when th
nvd
CVE-2023-22250P4MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22250 [MEDIUM] CWE-284 CVE-2023-22250: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Imprope Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
nvd
CVE-2022-35692P4MEDIUMCVSS 5.3v2.3.7v2.4.3+2 more2022-08-19
CVE-2022-35692 [MEDIUM] CWE-863 CVE-2022-35692: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require
nvd
CVE-2023-29291P4MEDIUMCVSS 4.9≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29291 [MEDIUM] CWE-918 CVE-2023-29291: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation o
nvd
CVE-2023-29292P4MEDIUMCVSS 4.9≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29292 [MEDIUM] CWE-918 CVE-2023-29292: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation o
nvd
CVE-2021-36027P4MEDIUMCVSS 6.1≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36027 [MEDIUM] CWE-79 CVE-2021-36027: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vu
nvd
CVE-2023-29287P4MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29287 [MEDIUM] CWE-200 CVE-2023-29287: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability that could lead to a security feature bypass. An attacker could leverage this vulnerability to leak minor user data. Exploitation of this issue does not require user interaction..
nvd
CVE-2022-34257P4MEDIUMCVSS 6.1≥ unspecified, ≤ 2.4.42022-08-16
CVE-2022-34257 [MEDIUM] CWE-79 CVE-2022-34257: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing
nvd
CVE-2021-21027P4MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.12021-02-11
CVE-2021-21027 [MEDIUM] CWE-352 CVE-2021-21027: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exp
nvd
CVE-2020-24405P4MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24405 [MEDIUM] CWE-285 CVE-2020-24405: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulne Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.
nvd
CVE-2023-29296P4MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.5-p12023-06-15
CVE-2023-29296 [MEDIUM] CWE-863 CVE-2023-29296: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to modify a minor functionality of another user's data. Exploitation of this issue does not
nvd
CVE-2023-29294P4MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29294 [MEDIUM] CWE-840 CVE-2023-29294: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-29295P4MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-29295 [MEDIUM] CWE-863 CVE-2023-29295: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not require user interacti
nvd
CVE-2021-28583P4MEDIUMCVSS 4.2≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28583 [MEDIUM] CWE-657 CVE-2021-28583: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.
nvd
CVE-2021-21023P4MEDIUMCVSS 4.8≥ unspecified, ≤ 2.4.12021-02-11
CVE-2021-21023 [MEDIUM] CWE-79 CVE-2021-21023: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.
nvd
CVE-2021-28556P4MEDIUMCVSS 4.8≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28556 [MEDIUM] CWE-79 CVE-2021-28556: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
nvd
CVE-2023-22251P4MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22251 [MEDIUM] CWE-863 CVE-2023-22251: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorre Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
nvd
CVE-2020-24406P4LOWCVSS 3.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24406 [LOW] CWE-200 CVE-2020-24406: When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an informati When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attackers if they are able to identify other exploitable vulnerabilities in the environment.
nvd
CVE-2020-24403P4LOWCVSS 2.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24403 [LOW] CWE-285 CVE-2020-24403: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulner Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
nvd
CVE-2020-24404P4LOWCVSS 2.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24404 [LOW] CWE-285 CVE-2020-24404: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerabili Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
nvd
Adobe Magento Commerce vulnerabilities | cvebase