VendorsAdobemagento2.4.5
Vulnerabilities

Adobe Magento 2.4.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

137CVEs
CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
Published 2024-06-13 · Analyzed
9.8KEVEPSS 1.000
CVE-2024-45115
Adobe Commerce | Improper Authentication (CWE-287)
Published 2024-10-10 · Analyzed
9.8EPSS 0.013
CVE-2024-34107
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-06-13 · Modified
9.8EPSS 0.011
CVE-2025-54236
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2025-09-09 · Analyzed
9.1KEVEPSS 0.945
CVE-2025-24434
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-02-11 · Analyzed
9.1EPSS 0.172
CVE-2024-34108
Large attack surface through legit webhook usage in Adobe Commerce
Published 2024-06-13 · Modified
9.1EPSS 0.014
CVE-2023-29297
Admin-to-admin stored XSS via cache poisoning
Published 2023-06-15 · Modified
9.1EPSS 0.014
CVE-2024-20758
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2024-04-10 · Analyzed
9.0EPSS 0.014
CVE-2024-39397
Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2024-08-14 · Analyzed
9.0EPSS 0.011
CVE-2024-34111
SSRF in service connector
Published 2024-06-13 · Modified
8.8EPSS 0.013
CVE-2023-38218
Incorrect Authorization - Customer account takeover
Published 2023-10-13 · Modified
8.8EPSS 0.008
CVE-2024-45148
Adobe Commerce | Improper Authentication (CWE-287)
Published 2024-10-10 · Analyzed
8.8EPSS 0.007
CVE-2025-24438
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Modified
8.7EPSS 0.008
CVE-2025-24415
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24412
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24416
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24410
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24414
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24417
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-24413
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-02-11 · Analyzed
8.7EPSS 0.007
CVE-2025-49557
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-08-12 · Analyzed
8.7EPSS 0.006
CVE-2023-38219
Validate Your Inputs | Cross-site Scripting (Stored XSS) (CWE-79) - Customer to Admin stored XSS with Gift wrapping
Published 2023-10-13 · Modified
8.7EPSS 0.006
CVE-2026-21290
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.7EPSS 0.005
CVE-2024-39402
Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2024-08-14 · Analyzed
8.4EPSS 0.017
CVE-2024-39401
Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2024-08-14 · Analyzed
8.4EPSS 0.017
CVE-2025-47110
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-06-10 · Analyzed
8.4EPSS 0.007
CVE-2024-34104
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-06-13 · Modified
8.2EPSS 0.008
CVE-2025-24409
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-02-11 · Analyzed
8.2EPSS 0.007
CVE-2025-43585
Adobe Commerce | Improper Authorization (CWE-285)
Published 2025-06-10 · Analyzed
8.2EPSS 0.005
CVE-2024-20759
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-04-10 · Analyzed
8.1EPSS 0.010
CVE-2024-45116
Adobe Commerce | Cross-site Scripting (XSS) (CWE-79)
Published 2024-10-10 · Analyzed
8.1EPSS 0.009
CVE-2025-24411
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-02-11 · Analyzed
8.1EPSS 0.009
CVE-2024-34103
Customer account takeover via web API call & subsequent password reset
Published 2024-06-13 · Modified
8.1EPSS 0.009
CVE-2025-49555
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2025-08-12 · Analyzed
8.1EPSS 0.009
CVE-2024-39400
DOM XSS through integrations can impact other admins
Published 2024-08-14 · Analyzed
8.1EPSS 0.007
CVE-2025-43586
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-06-10 · Analyzed
8.1EPSS 0.006
CVE-2026-21361
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2026-21284
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2023-38221
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
CVE-2023-38249
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2023-10-13 · Modified
8.0EPSS 0.008
1 / 4Next →