VendorsAdobecommerceall versions
Vulnerabilities

Adobe Commerce

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

208CVEs
CVE-2023-22247
Adobe Commerce XML Injection Arbitrary file system read
Published 2023-03-27 · Modified
7.5EPSS 0.009
CVE-2026-34651
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34650
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34652
Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34649
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-77108
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
7.5EPSS 0.008
CVE-2026-34645
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2026-34646
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2023-38220
Full page cache enumeration via cookie X-Magento-Vary
Published 2023-10-13 · Modified
7.5EPSS 0.007
CVE-2026-21289
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-03-11 · Analyzed
7.5EPSS 0.006
CVE-2025-49556
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-08-12 · Analyzed
7.5EPSS 0.006
CVE-2025-49554
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2025-08-12 · Analyzed
7.5EPSS 0.006
CVE-2026-21309
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-03-11 · Analyzed
7.5EPSS 0.006
CVE-2026-34647
Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-05-12 · Analyzed
7.4EPSS 0.009
CVE-2024-39398
OTP 2FA can be bruteforced
Published 2024-08-14 · Analyzed
7.4EPSS 0.009
CVE-2024-34109
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-06-13 · Modified
7.2EPSS 0.014
CVE-2024-34110
RCE in the Adobe Commerce Webhook module through a legit webhook definition
Published 2024-06-13 · Modified
7.2EPSS 0.014
CVE-2026-47992
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-07-14 · Analyzed
7.2EPSS 0.010
CVE-2026-47996
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
6.8EPSS 0.009
CVE-2024-39406
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2024-08-14 · Analyzed
6.8EPSS 0.009
CVE-2023-26366
Validate Your Inputs | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2023-10-13 · Modified
6.8EPSS 0.007
CVE-2026-21360
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-03-11 · Analyzed
6.8EPSS 0.006
CVE-2021-39864
Adobe Commerce Cross-Site Request Forgery (CSRF) Could Lead To Unauthorized Cart Addition
Published 2021-10-15 · Modified
6.5EPSS 0.016
CVE-2025-24408
Adobe Commerce | Information Exposure (CWE-200)
Published 2025-02-11 · Analyzed
6.5EPSS 0.010
CVE-2023-29289
Adobe Commerce XML Injection Security feature bypass
Published 2023-06-15 · Modified
6.5EPSS 0.009
CVE-2023-38209
Adobe Commerce Incorrect Authorization Security feature bypass
Published 2023-08-09 · Modified
6.5EPSS 0.009
CVE-2024-20718
[Spain] CSRF to delete Requisition Lists at Adobe Commerce
Published 2024-02-15 · Modified
6.5EPSS 0.008
CVE-2024-45132
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2024-10-10 · Modified
6.5EPSS 0.007
CVE-2024-45118
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
6.5EPSS 0.006
CVE-2025-24427
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-02-11 · Analyzed
6.5EPSS 0.006
CVE-2025-54267
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-10-14 · Analyzed
6.5EPSS 0.004
CVE-2022-34257
Adobe Commerce Stored XSS Arbitrary code execution
Published 2022-08-16 · Modified
6.1EPSS 0.010
CVE-2024-45123
Adobe Commerce | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2024-10-10 · Analyzed
6.1EPSS 0.005
CVE-2026-48000
Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
Published 2026-07-14 · Analyzed
6.1EPSS 0.005
CVE-2026-47998
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
5.9EPSS 0.007
CVE-2026-47997
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
5.9EPSS 0.007
CVE-2025-54265
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-10-14 · Analyzed
5.9EPSS 0.006
CVE-2025-49558
Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Published 2025-08-12 · Analyzed
5.9EPSS 0.004
CVE-2026-21293
Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-03-11 · Analyzed
5.5EPSS 0.002
CVE-2026-21294
Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-03-11 · Analyzed
5.5EPSS 0.002
← Prev3 / 6Next →