VendorsAdobecommerceany version
Vulnerabilities

Adobe Commerce any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

138CVEs
CVE-2024-39418
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-08-14 · Analyzed
5.4EPSS 0.004
CVE-2026-21292
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
5.4EPSS 0.003
CVE-2022-34259
Adobe Commerce Improper Access Control Security feature bypass
Published 2022-08-16 · Modified
5.3EPSS 0.016
CVE-2022-35689
Adobe Commerce Improper Access Control Security feature bypass
Published 2022-10-14 · Modified
5.3EPSS 0.013
CVE-2023-22250
Adobe Commerce Improper Access Control Security feature bypass
Published 2023-03-27 · Modified
5.3EPSS 0.010
CVE-2022-35692
Adobe Commerce Improper Access Control Security feature bypass
Published 2022-08-19 · Modified
5.3EPSS 0.008
CVE-2026-34654
Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
Published 2026-05-12 · Analyzed
5.3EPSS 0.008
CVE-2025-49559
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-08-12 · Analyzed
5.3EPSS 0.007
CVE-2025-24425
Adobe Commerce | Business Logic Errors (CWE-840)
Published 2025-02-11 · Analyzed
5.3EPSS 0.006
CVE-2024-45124
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
5.3EPSS 0.006
CVE-2026-21282
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2026-03-11 · Analyzed
5.3EPSS 0.005
CVE-2025-27191
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-04-08 · Analyzed
5.3EPSS 0.005
CVE-2026-21310
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2026-03-11 · Analyzed
5.3EPSS 0.003
CVE-2026-21286
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-03-11 · Analyzed
5.3EPSS 0.003
CVE-2022-34258
Adobe Commerce Stored XSS Arbitrary code execution
Published 2022-08-16 · Modified
4.8EPSS 0.685
CVE-2023-22249
Adobe Commerce Stored XSS Arbitrary code execution
Published 2023-03-27 · Modified
4.8EPSS 0.585
CVE-2024-45127
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-10-10 · Analyzed
4.8EPSS 0.005
CVE-2026-34658
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-05-12 · Analyzed
4.8EPSS 0.004
CVE-2026-34655
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-05-12 · Analyzed
4.8EPSS 0.004
CVE-2026-21291
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
4.8EPSS 0.003
CVE-2026-21359
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-03-11 · Analyzed
4.7EPSS 0.002
CVE-2026-34656
Adobe Commerce | Improper Authorization (CWE-285)
Published 2026-05-12 · Analyzed
4.3EPSS 0.006
CVE-2025-27188
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-04-08 · Analyzed
4.3EPSS 0.006
CVE-2023-22251
Adobe Commerce Incorrect Authorization Security feature bypass
Published 2023-03-27 · Modified
4.3EPSS 0.006
CVE-2024-45122
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.006
CVE-2025-24421
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-02-11 · Analyzed
4.3EPSS 0.005
CVE-2024-45121
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2024-45125
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2024-45129
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2024-45130
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
4.3EPSS 0.005
CVE-2024-39408
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39409
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39410
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39404
A user without Shop Policy Parameters section privilege can alter the shop policy parameters section
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39411
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39413
An unauthorized user can export the Invoiced Sales Report
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39414
Being able to import/export tax rates without proper privileges
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39415
An unauthorized user can export the Tax Sales Report
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39417
An unauthorized user can export the Shipping Report
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39405
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
← Prev3 / 4Next →