VendorsOraclecommerce_merchandisingall versions
Vulnerabilities

Oracle Commerce Merchandising

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-32808
Cross-site scripting in ckeditor via abuse of undo functionality
Published 2021-08-12 · Modified
7.6EPSS 0.012
CVE-2022-24729
Regular expression Denial of Service in dialog plugin
Published 2022-03-16 · Modified
7.5EPSS 0.025
CVE-2021-37695
Execution of JavaScript code using malformed HTML in ckeditor
Published 2021-08-12 · Modified
7.3EPSS 0.013
CVE-2021-26272
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Published 2021-01-26 · Modified
6.5EPSS 0.022
CVE-2019-2713
Vulnerability in the Oracle Commerce Merchandising component of Oracle Commerce (subcomponent: Asset Manager). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Merchandising. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Merchandising accessible data as well as unauthorized read access to a subset of Oracle Commerce Merchandising accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published 2019-04-23 · Modified
6.5EPSS 0.010
CVE-2020-27193
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Published 2020-11-12 · Modified
6.1EPSS 0.020
CVE-2022-24728
Cross-site Scripting in CKEditor4
Published 2022-03-16 · Modified
5.4EPSS 0.012
CVE-2021-32809
Arbitrary HTML injection vulnerability in ckeditor
Published 2021-08-12 · Modified
5.4EPSS 0.012