VendorsAdobecommerce2.3.7
Vulnerabilities

Adobe Commerce 2.3.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

62CVEs
CVE-2023-38251
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2023-10-13 · Modified
5.3EPSS 0.007
CVE-2023-29290
Adobe Commerce Guest Cart Shipping Address Overwrite IDOR
Published 2023-06-15 · Modified
5.3EPSS 0.006
CVE-2024-45124
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
5.3EPSS 0.006
CVE-2023-29291
Server Side Request Forgery (SSRF) in USPS carrier integration configuration
Published 2023-06-15 · Modified
4.9EPSS 0.011
CVE-2023-29292
Server Side Request Forgery (SSRF) in FedEx carrier integration configuration
Published 2023-06-15 · Modified
4.9EPSS 0.010
CVE-2023-26367
Error based file extraction via PHP filter chains during product bulk import logic
Published 2023-10-13 · Modified
4.9EPSS 0.007
CVE-2022-34258
Adobe Commerce Stored XSS Arbitrary code execution
Published 2022-08-16 · Modified
4.8EPSS 0.685
CVE-2024-34105
Stored Cross Site Scripting in Order Comment
Published 2024-06-13 · Modified
4.8EPSS 0.007
CVE-2024-45127
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-10-10 · Analyzed
4.8EPSS 0.005
CVE-2023-29294
Bypass Purchase Order Approval using Company User in Adobe Commerce B2B
Published 2023-06-15 · Modified
4.3EPSS 0.007
CVE-2023-29288
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2023-06-15 · Modified
4.3EPSS 0.006
CVE-2023-29296
[Cloud] Customer suspects IDOR vulnerability
Published 2023-06-15 · Modified
4.3EPSS 0.006
CVE-2023-29295
Insecure Direct Object Reference (IDOR) in Create Quote Function
Published 2023-06-15 · Modified
4.3EPSS 0.006
CVE-2024-45122
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.006
CVE-2024-45125
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2024-45129
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2024-45130
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2024-45121
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2023-29293
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2023-06-15 · Modified
2.7EPSS 0.010
CVE-2024-45134
Adobe Commerce | Information Exposure (CWE-200)
Published 2024-10-10 · Analyzed
2.7EPSS 0.006
CVE-2024-45133
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
2.7EPSS 0.006
CVE-2024-45135
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
2.7EPSS 0.006
← Prev2 / 2