VendorsAdobecommerceall versions
Vulnerabilities

Adobe Commerce

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

208CVEs
CVE-2026-34686
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-05-12 · Analyzed
8.7EPSS 0.007
CVE-2025-49557
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-08-12 · Analyzed
8.7EPSS 0.006
CVE-2023-38219
Validate Your Inputs | Cross-site Scripting (Stored XSS) (CWE-79) - Customer to Admin stored XSS with Gift wrapping
Published 2023-10-13 · Modified
8.7EPSS 0.006
CVE-2026-21290
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.7EPSS 0.005
CVE-2026-77774
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.6EPSS 0.008
CVE-2026-47988
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
8.6EPSS 0.008
CVE-2026-77109
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.6EPSS 0.007
CVE-2024-39401
Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2024-08-14 · Analyzed
8.4EPSS 0.017
CVE-2024-39402
Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2024-08-14 · Analyzed
8.4EPSS 0.017
CVE-2025-47110
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-06-10 · Analyzed
8.4EPSS 0.007
CVE-2024-34104
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-06-13 · Modified
8.2EPSS 0.008
CVE-2026-47984
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
8.2EPSS 0.007
CVE-2025-24409
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-02-11 · Analyzed
8.2EPSS 0.007
CVE-2026-76202
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.2EPSS 0.007
CVE-2025-43585
Adobe Commerce | Improper Authorization (CWE-285)
Published 2025-06-10 · Analyzed
8.2EPSS 0.005
CVE-2024-20759
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-04-10 · Analyzed
8.1EPSS 0.010
CVE-2024-45116
Adobe Commerce | Cross-site Scripting (XSS) (CWE-79)
Published 2024-10-10 · Analyzed
8.1EPSS 0.009
CVE-2025-24411
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-02-11 · Analyzed
8.1EPSS 0.009
CVE-2024-34103
Customer account takeover via web API call & subsequent password reset
Published 2024-06-13 · Modified
8.1EPSS 0.009
CVE-2025-49555
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2025-08-12 · Analyzed
8.1EPSS 0.009
CVE-2026-47995
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-07-14 · Analyzed
8.1EPSS 0.007
CVE-2024-39400
DOM XSS through integrations can impact other admins
Published 2024-08-14 · Analyzed
8.1EPSS 0.007
CVE-2025-54264
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-10-14 · Analyzed
8.1EPSS 0.006
CVE-2025-54263
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-10-14 · Analyzed
8.1EPSS 0.006
CVE-2025-43586
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-06-10 · Analyzed
8.1EPSS 0.006
CVE-2026-21361
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2026-21284
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2023-38250
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2023-38249
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2023-38221
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2026-21311
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.0EPSS 0.003
CVE-2024-39399
[Paris] Path Traversal lead to local file read
Published 2024-08-14 · Analyzed
7.7EPSS 0.009
CVE-2024-49521
Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2024-11-12 · Analyzed
7.7EPSS 0.007
CVE-2026-77110
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-09-08 · Analyzed
7.6EPSS 0.011
CVE-2024-45117
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-10-10 · Analyzed
7.6EPSS 0.008
CVE-2024-39403
Stored XSS through Webhook module public key configuration
Published 2024-08-14 · Analyzed
7.6EPSS 0.005
CVE-2025-24406
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-02-11 · Analyzed
7.5EPSS 0.014
CVE-2026-34648
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.010
CVE-2023-22248
Adobe Commerce Incorrect Authorization Security feature bypass
Published 2023-06-15 · Modified
7.5EPSS 0.010
CVE-2023-38207
Adobe Commerce XML Injection (aka Blind XPath Injection) Arbitrary file system read
Published 2023-08-09 · Modified
7.5EPSS 0.009
← Prev2 / 6Next →