VendorsAdobemagentoall versions
Vulnerabilities

Adobe Magento

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

185CVEs
CVE-2024-34104
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-06-13 · Modified
8.2EPSS 0.008
CVE-2026-47984
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
8.2EPSS 0.007
CVE-2025-24409
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-02-11 · Analyzed
8.2EPSS 0.007
CVE-2026-76202
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.2EPSS 0.007
CVE-2025-43585
Adobe Commerce | Improper Authorization (CWE-285)
Published 2025-06-10 · Analyzed
8.2EPSS 0.005
CVE-2020-8818
An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.
Published 2020-02-25 · Modified
8.1EPSS 0.042
CVE-2021-21013
Magento Commerce Insecure Direct Object Reference Could Lead To Information Disclosure
Published 2021-01-13 · Modified
8.1EPSS 0.032
CVE-2024-20759
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-04-10 · Analyzed
8.1EPSS 0.010
CVE-2024-45116
Adobe Commerce | Cross-site Scripting (XSS) (CWE-79)
Published 2024-10-10 · Analyzed
8.1EPSS 0.009
CVE-2025-24411
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-02-11 · Analyzed
8.1EPSS 0.009
CVE-2024-34103
Customer account takeover via web API call & subsequent password reset
Published 2024-06-13 · Modified
8.1EPSS 0.009
CVE-2025-49555
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2025-08-12 · Analyzed
8.1EPSS 0.009
CVE-2026-47995
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-07-14 · Analyzed
8.1EPSS 0.007
CVE-2024-39400
DOM XSS through integrations can impact other admins
Published 2024-08-14 · Analyzed
8.1EPSS 0.007
CVE-2025-54264
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-10-14 · Analyzed
8.1EPSS 0.006
CVE-2025-54263
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-10-14 · Analyzed
8.1EPSS 0.006
CVE-2025-43586
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-06-10 · Analyzed
8.1EPSS 0.006
CVE-2026-21361
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2026-21284
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2023-38250
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2023-38249
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2023-38221
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2026-21311
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.0EPSS 0.003
CVE-2024-39399
[Paris] Path Traversal lead to local file read
Published 2024-08-14 · Analyzed
7.7EPSS 0.009
CVE-2024-49521
Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2024-11-12 · Analyzed
7.7EPSS 0.007
CVE-2026-77110
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-09-08 · Analyzed
7.6EPSS 0.011
CVE-2024-45117
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-10-10 · Analyzed
7.6EPSS 0.008
CVE-2024-39403
Stored XSS through Webhook module public key configuration
Published 2024-08-14 · Analyzed
7.6EPSS 0.005
CVE-2025-24406
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-02-11 · Analyzed
7.5EPSS 0.014
CVE-2026-34648
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.010
CVE-2023-22248
Adobe Commerce Incorrect Authorization Security feature bypass
Published 2023-06-15 · Modified
7.5EPSS 0.010
CVE-2026-34650
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34651
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34649
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34652
Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-77108
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
7.5EPSS 0.008
CVE-2026-34646
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2026-34645
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2023-38220
Full page cache enumeration via cookie X-Magento-Vary
Published 2023-10-13 · Modified
7.5EPSS 0.007
CVE-2026-21289
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-03-11 · Analyzed
7.5EPSS 0.006
← Prev2 / 5Next →