VendorsAdobecommerce2.4.2
Vulnerabilities

Adobe Commerce 2.4.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
Published 2024-06-13 · Analyzed
9.8KEVEPSS 1.000
CVE-2024-45115
Adobe Commerce | Improper Authentication (CWE-287)
Published 2024-10-10 · Analyzed
9.8EPSS 0.013
CVE-2024-34107
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-06-13 · Modified
9.8EPSS 0.011
CVE-2024-34108
Large attack surface through legit webhook usage in Adobe Commerce
Published 2024-06-13 · Modified
9.1EPSS 0.014
CVE-2023-29297
Admin-to-admin stored XSS via cache poisoning
Published 2023-06-15 · Modified
9.1EPSS 0.014
CVE-2024-20758
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-04-10 · Analyzed
9.0EPSS 0.014
CVE-2024-34111
SSRF in service connector
Published 2024-06-13 · Modified
8.8EPSS 0.013
CVE-2023-38218
Incorrect Authorization - Customer account takeover
Published 2023-10-13 · Modified
8.8EPSS 0.008
CVE-2024-45148
Adobe Commerce | Improper Authentication (CWE-287)
Published 2024-10-10 · Analyzed
8.8EPSS 0.007
CVE-2023-38219
Validate Your Inputs | Cross-site Scripting (Stored XSS) (CWE-79) - Customer to Admin stored XSS with Gift wrapping
Published 2023-10-13 · Modified
8.7EPSS 0.006
CVE-2024-34104
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-06-13 · Modified
8.2EPSS 0.008
CVE-2024-20759
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-04-10 · Analyzed
8.1EPSS 0.010
CVE-2024-45116
Adobe Commerce | Cross-site Scripting (XSS) (CWE-79)
Published 2024-10-10 · Analyzed
8.1EPSS 0.009
CVE-2024-34103
Customer account takeover via web API call & subsequent password reset
Published 2024-06-13 · Modified
8.1EPSS 0.009
CVE-2023-38221
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2023-38250
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2023-38249
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2024-45117
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-10-10 · Analyzed
7.6EPSS 0.008
CVE-2023-22248
Adobe Commerce Incorrect Authorization Security feature bypass
Published 2023-06-15 · Modified
7.5EPSS 0.010
CVE-2023-38220
Full page cache enumeration via cookie X-Magento-Vary
Published 2023-10-13 · Modified
7.5EPSS 0.007
CVE-2024-34109
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-06-13 · Modified
7.2EPSS 0.014
CVE-2024-34110
RCE in the Adobe Commerce Webhook module through a legit webhook definition
Published 2024-06-13 · Modified
7.2EPSS 0.014
CVE-2023-26366
Validate Your Inputs | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2023-10-13 · Modified
6.8EPSS 0.007
CVE-2021-39864
Adobe Commerce Cross-Site Request Forgery (CSRF) Could Lead To Unauthorized Cart Addition
Published 2021-10-15 · Modified
6.5EPSS 0.016
CVE-2023-29289
Adobe Commerce XML Injection Security feature bypass
Published 2023-06-15 · Modified
6.5EPSS 0.009
CVE-2024-45132
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2024-10-10 · Modified
6.5EPSS 0.007
CVE-2024-45118
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
6.5EPSS 0.006
CVE-2024-45123
Adobe Commerce | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2024-10-10 · Analyzed
6.1EPSS 0.005
CVE-2024-45128
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2024-10-10 · Modified
5.4EPSS 0.006
CVE-2024-45131
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2024-10-10 · Modified
5.4EPSS 0.005
CVE-2024-34106
Insecure Direct Object Reference - An attacker can able to erase the victim quote details
Published 2024-06-13 · Modified
5.3EPSS 0.008
CVE-2023-29287
Adobe Commerce Information Exposure Security feature bypass
Published 2023-06-15 · Modified
5.3EPSS 0.007
CVE-2023-38251
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2023-10-13 · Modified
5.3EPSS 0.007
CVE-2023-29290
Adobe Commerce Guest Cart Shipping Address Overwrite IDOR
Published 2023-06-15 · Modified
5.3EPSS 0.006
CVE-2024-45124
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
5.3EPSS 0.006
CVE-2023-29291
Server Side Request Forgery (SSRF) in USPS carrier integration configuration
Published 2023-06-15 · Modified
4.9EPSS 0.011
CVE-2023-29292
Server Side Request Forgery (SSRF) in FedEx carrier integration configuration
Published 2023-06-15 · Modified
4.9EPSS 0.010
CVE-2023-26367
Error based file extraction via PHP filter chains during product bulk import logic
Published 2023-10-13 · Modified
4.9EPSS 0.007
CVE-2024-34105
Stored Cross Site Scripting in Order Comment
Published 2024-06-13 · Modified
4.8EPSS 0.007
CVE-2024-45127
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-10-10 · Analyzed
4.8EPSS 0.005
1 / 2Next →