VendorsAdobemagento2.4.9
Vulnerabilities

Adobe Magento 2.4.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

70CVEs
CVE-2026-75650
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Published 2026-09-07 · Analyzed
10.0KEVEPSS 0.039
CVE-2026-48356
Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2026-07-14 · Analyzed
9.3EPSS 0.010
CVE-2026-76200
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-09-08 · Analyzed
9.3EPSS 0.007
CVE-2026-76201
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-09-08 · Analyzed
9.3EPSS 0.007
CVE-2025-54236
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2025-09-09 · Analyzed
9.1KEVEPSS 0.945
CVE-2026-71362
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Modified
9.1KEVEPSS 0.023
CVE-2026-48358
Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)
Published 2026-07-14 · Analyzed
9.1EPSS 0.012
CVE-2026-34653
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-05-12 · Analyzed
8.7EPSS 0.010
CVE-2026-77111
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.7EPSS 0.008
CVE-2026-34686
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-05-12 · Analyzed
8.7EPSS 0.007
CVE-2026-47994
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-07-14 · Analyzed
8.7EPSS 0.007
CVE-2025-49557
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-08-12 · Analyzed
8.7EPSS 0.006
CVE-2026-21290
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.7EPSS 0.005
CVE-2026-77774
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.6EPSS 0.008
CVE-2026-47988
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
8.6EPSS 0.008
CVE-2026-77109
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.6EPSS 0.007
CVE-2026-47984
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
8.2EPSS 0.007
CVE-2026-76202
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.2EPSS 0.007
CVE-2025-49555
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2025-08-12 · Analyzed
8.1EPSS 0.009
CVE-2026-47995
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-07-14 · Analyzed
8.1EPSS 0.007
CVE-2025-54264
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-10-14 · Analyzed
8.1EPSS 0.006
CVE-2025-54263
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-10-14 · Analyzed
8.1EPSS 0.006
CVE-2026-21361
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2026-21284
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.1EPSS 0.004
CVE-2026-21311
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-03-11 · Analyzed
8.0EPSS 0.003
CVE-2026-77110
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-09-08 · Analyzed
7.6EPSS 0.011
CVE-2026-34648
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.010
CVE-2026-34649
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34650
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34651
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-34652
Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-77108
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
7.5EPSS 0.008
CVE-2026-34645
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2026-34646
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2026-21289
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-03-11 · Analyzed
7.5EPSS 0.006
CVE-2025-49556
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2025-08-12 · Analyzed
7.5EPSS 0.006
CVE-2025-49554
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2025-08-12 · Analyzed
7.5EPSS 0.006
CVE-2026-21309
Adobe Commerce | Incorrect Authorization (CWE-863)
Published 2026-03-11 · Analyzed
7.5EPSS 0.006
CVE-2026-34647
Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-05-12 · Analyzed
7.4EPSS 0.009
CVE-2026-47992
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-07-14 · Analyzed
7.2EPSS 0.010
1 / 2Next →