VendorsAdobecommerceany version
Vulnerabilities

Adobe Commerce any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

138CVEs
CVE-2022-24086
Adobe Commerce checkout improper input validation leads to remote code execution
Published 2022-02-16 · Analyzed
10.0KEVEPSS 0.992
CVE-2022-35698
Adobe Commerce Stored XSS Arbitrary code execution
Published 2022-10-14 · Modified
10.0EPSS 0.109
CVE-2026-75650
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Published 2026-09-07 · Analyzed
10.0KEVEPSS 0.039
CVE-2022-34256
Adobe Commerce Improper Authorization Privilege escalation
Published 2022-08-16 · Modified
9.8EPSS 0.021
CVE-2024-45115
Adobe Commerce | Improper Authentication (CWE-287)
Published 2024-10-10 · Analyzed
9.8EPSS 0.013
CVE-2026-76201
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-09-08 · Analyzed
9.3EPSS 0.007
CVE-2026-76200
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-09-08 · Analyzed
9.3EPSS 0.007
CVE-2026-71362
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
9.1KEVEPSS 0.896
CVE-2022-34253
Adobe Commerce XML Injection Arbitrary code execution
Published 2022-08-16 · Modified
9.1EPSS 0.049
CVE-2023-38208
Validate Your Inputs | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2023-08-09 · Modified
9.1EPSS 0.023
CVE-2022-24093
Adobe Commerce post-auth improper input validation leads to remote code execution
Published 2023-09-12 · Modified
9.1EPSS 0.015
CVE-2024-20758
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-04-10 · Analyzed
9.0EPSS 0.014
CVE-2024-39397
Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2024-08-14 · Analyzed
9.0EPSS 0.011
CVE-2022-34255
Adobe Commerce Improper Access Control Privilege escalation
Published 2022-08-16 · Modified
8.8EPSS 0.022
CVE-2022-34254
Adobe Commerce Improper Limitation of a Pathname to a Restricted Directory Arbitrary code execution
Published 2022-08-16 · Modified
8.8EPSS 0.022
CVE-2022-42344
[CVE-2021-36032] Magento IDOR Leads to Account Takeover
Published 2022-10-20 · Modified
8.8EPSS 0.012
CVE-2024-45148
Adobe Commerce | Improper Authentication (CWE-287)
Published 2024-10-10 · Analyzed
8.8EPSS 0.007
CVE-2026-34653
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-05-12 · Analyzed
8.7EPSS 0.010
CVE-2026-77111
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.7EPSS 0.008
CVE-2025-24412
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24413
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24415
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24416
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24410
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24417
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24414
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-49557
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-08-12 · Analyzed
8.7EPSS 0.006
CVE-2026-21290
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.7EPSS 0.005
CVE-2026-77774
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.6EPSS 0.008
CVE-2026-77109
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.6EPSS 0.007
CVE-2024-39401
Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2024-08-14 · Analyzed
8.4EPSS 0.017
CVE-2024-39402
Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2024-08-14 · Analyzed
8.4EPSS 0.017
CVE-2025-24409
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-02-11 · Analyzed
8.2EPSS 0.007
CVE-2026-76202
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.2EPSS 0.007
CVE-2024-20759
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-04-10 · Analyzed
8.1EPSS 0.010
CVE-2024-45116
Adobe Commerce | Cross-site Scripting (XSS) (CWE-79)
Published 2024-10-10 · Analyzed
8.1EPSS 0.009
CVE-2025-24411
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-02-11 · Analyzed
8.1EPSS 0.009
CVE-2025-49555
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2025-08-12 · Analyzed
8.1EPSS 0.009
CVE-2024-39400
DOM XSS through integrations can impact other admins
Published 2024-08-14 · Analyzed
8.1EPSS 0.007
CVE-2026-21361
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
1 / 4Next →