Adobe Magento Open Source vulnerabilities
46 known vulnerabilities affecting adobe/magento_open_source.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH18MEDIUM22LOW1
Vulnerabilities
Page 3 of 3
CVE-2023-22250P4MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22250 [MEDIUM] CWE-284 CVE-2023-22250: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Imprope
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-48371P4MEDIUMCVSS 5.4≤ 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p152026-07-14
CVE-2026-48371 [MEDIUM] CWE-79 CVE-2026-48371: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2021-36027P4MEDIUMCVSS 6.1≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36027 [MEDIUM] CWE-79 CVE-2021-36027: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vu
nvd
CVE-2026-47995P4MEDIUMCVSS 4.8≤ 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p152026-07-14
CVE-2026-47995 [MEDIUM] CWE-79 CVE-2026-47995: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or cont
nvd
CVE-2023-22251P4MEDIUMCVSS 4.3fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22251 [MEDIUM] CWE-863 CVE-2023-22251: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorre
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
nvd
CVE-2026-48001P4LOWCVSS 3.7≤ 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p152026-07-14
CVE-2026-48001 [LOW] CWE-200 CVE-2026-48001: Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited dis
Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
nvd
← Previous3 / 3