Oracle Commerce Guided Search vulnerabilities
70 known vulnerabilities affecting oracle/commerce_guided_search.
Total CVEs
70
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH43MEDIUM20LOW1
Vulnerabilities
Page 4 of 4
CVE-2021-32809P4MEDIUMCVSS 5.4v11.3.22021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2021-41165P4MEDIUMCVSS 5.4v11.3.22021-11-17
CVE-2021-41165 [MEDIUM] CWE-79 CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discov
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users usi
nvd
CVE-2021-32808P4MEDIUMCVSS 5.4v11.3.22021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
nvd
CVE-2026-61147P4MEDIUMCVSS 6.2v11.4.02026-07-21
CVE-2026-61147 [MEDIUM] CWE-400 CVE-2026-61147: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Co
nvd
CVE-2021-37695P4MEDIUMCVSS 5.4v11.3.22021-08-13
CVE-2021-37695 [MEDIUM] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdi
nvd
CVE-2021-41164P4MEDIUMCVSS 5.4v11.3.22021-11-17
CVE-2021-41164 [MEDIUM] CWE-79 CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been disco
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users us
nvd
CVE-2021-2345P4MEDIUMCVSS 5.4v11.3.1.52021-07-21
CVE-2021-2345 [MEDIUM] CVE-2021-2345: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Expe
nvd
CVE-2021-2346P4MEDIUMCVSS 5.4v11.3.1.52021-07-21
CVE-2021-2346 [MEDIUM] CVE-2021-2346: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Expe
nvd
CVE-2021-2348P4MEDIUMCVSS 4.3v11.3.1.52021-07-21
CVE-2021-2348 [MEDIUM] CVE-2021-2348: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Expe
nvd
CVE-2020-8908P4LOWCVSS 3.3v11.3.22020-12-10
CVE-2020-8908 [LOW] CWE-378 CVE-2020-8908: A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with a
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to
nvd
← Previous4 / 4