VendorsAdobecommerce_webhooksall versions
Vulnerabilities

Adobe Commerce Webhooks

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
Published 2024-06-13 · Analyzed
9.8KEVEPSS 1.000
CVE-2024-34107
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-06-13 · Modified
9.8EPSS 0.011
CVE-2024-34108
Large attack surface through legit webhook usage in Adobe Commerce
Published 2024-06-13 · Modified
9.1EPSS 0.014
CVE-2024-34111
SSRF in service connector
Published 2024-06-13 · Modified
8.8EPSS 0.013
CVE-2024-34104
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-06-13 · Modified
8.2EPSS 0.008
CVE-2024-34103
Customer account takeover via web API call & subsequent password reset
Published 2024-06-13 · Modified
8.1EPSS 0.009
CVE-2024-34109
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-06-13 · Modified
7.2EPSS 0.014
CVE-2024-34110
RCE in the Adobe Commerce Webhook module through a legit webhook definition
Published 2024-06-13 · Modified
7.2EPSS 0.014
CVE-2024-34106
Insecure Direct Object Reference - An attacker can able to erase the victim quote details
Published 2024-06-13 · Modified
5.3EPSS 0.008
CVE-2024-34105
Stored Cross Site Scripting in Order Comment
Published 2024-06-13 · Modified
4.8EPSS 0.007