Adobe Magento Open Source vulnerabilities
46 known vulnerabilities affecting adobe/magento_open_source.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH18MEDIUM22LOW1
Vulnerabilities
Page 2 of 3
CVE-2021-36041P3HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36041 [HIGH] CWE-20 CVE-2021-36041: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could upload a specially crafted file in the 'pub/media` directory could lead to remote code execution.
nvd
CVE-2021-36029P3HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36029 [HIGH] CWE-285 CVE-2021-36029: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
nvd
CVE-2023-22247P3HIGHCVSS 7.5fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22247 [HIGH] CWE-91 CVE-2023-22247: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Inj
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
nvd
CVE-2022-24093P3HIGHCVSS 7.2fixed in 2.3.7≥ 2.4.0, < 2.4.3+2 more2023-09-12
CVE-2022-24093 [HIGH] CWE-20 CVE-2022-24093: Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an imprope
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
nvd
CVE-2023-22249P3MEDIUMCVSS 4.8fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22249 [MEDIUM] CWE-79 CVE-2023-22249: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored C
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the v
nvd
CVE-2021-36044P3HIGHCVSS 7.5≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36044 [HIGH] CWE-20 CVE-2021-36044: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.
nvd
CVE-2021-36043P3MEDIUMCVSS 6.6≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36043 [MEDIUM] CWE-918 CVE-2021-36043: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.
nvd
CVE-2026-47998P3MEDIUMCVSS 5.9≤ 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p152026-07-14
CVE-2026-47998 [MEDIUM] CWE-863 CVE-2026-47998: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Securi
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
nvd
CVE-2021-36037P3MEDIUMCVSS 6.5≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36037 [MEDIUM] CWE-285 CVE-2021-36037: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
nvd
CVE-2021-36012P3MEDIUMCVSS 6.5≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36012 [MEDIUM] CWE-840 CVE-2021-36012: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.
nvd
CVE-2021-36038P3MEDIUMCVSS 6.5≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36038 [MEDIUM] CWE-20 CVE-2021-36038: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the Multishipping Module. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
nvd
CVE-2021-36039P3MEDIUMCVSS 6.5≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36039 [MEDIUM] CWE-863 CVE-2021-36039: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the `quoteId` parameter. An attacker can abuse this vulnerability to disclose sensitive information.
nvd
CVE-2022-35698P4MEDIUMCVSS 5.4fixed in 2.4.4v2.4.4+1 more2022-10-14
CVE-2022-35698 [MEDIUM] CWE-79 CVE-2022-35698: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cros
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
nvd
CVE-2021-39864P4MEDIUMCVSS 6.5≤ 2.3.7v2.3.7+2 more2021-10-15
CVE-2021-39864 [MEDIUM] CWE-352 CVE-2021-39864: Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are af
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for success
nvd
CVE-2026-47999P4MEDIUMCVSS 4.8≤ 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p152026-07-14
CVE-2026-47999 [MEDIUM] CWE-79 CVE-2026-47999: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-48000P4MEDIUMCVSS 6.1≤ 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p152026-07-14
CVE-2026-48000 [MEDIUM] CWE-601 CVE-2026-48000: Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result i
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a
nvd
CVE-2022-35689P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+1 more2022-10-14
CVE-2022-35689 [MEDIUM] CWE-284 CVE-2022-35689: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper A
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-47994P4MEDIUMCVSS 5.4≤ 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p152026-07-14
CVE-2026-47994 [MEDIUM] CWE-79 CVE-2026-47994: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or contr
nvd
CVE-2021-21012P4MEDIUMCVSS 5.3≤ 2.3.6v2.4.0+1 more2021-01-13
CVE-2021-21012 [MEDIUM] CWE-639 CVE-2021-21012: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2021-36026P4MEDIUMCVSS 6.1≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36026 [MEDIUM] CWE-79 CVE-2021-36026: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when th
nvd