Every advisory we track
The whole index, synced from the National Vulnerability Database and CISA's Known Exploited Vulnerabilities catalogue. The page used to print the number and not the list, which is a figure nobody can check.
Tracked is not the same as reported. A scan raises a finding only where we have written the step-by-step repair for it, because an exact fix command cannot be generated honestly from a CVE record. The right-hand column says which is which, and what changed records every time one moves from one column to the other.
| Advisory | CVSS | Exploited | Published | On a report? |
|---|---|---|---|---|
|
CVE-2026-75650
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code exec… |
10.0 | in the wild KEV 2026-09-08 | 2026-09-07 | StyleSmuggler |
|
CVE-2024-34102
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vuln… |
9.8 | in the wild KEV 2024-07-17 | 2024-06-13 | CosmicSting |
|
CVE-2022-24086
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout proc… |
9.8 | in the wild KEV 2022-02-15 | 2022-02-16 | TrojanOrder |
|
CVE-2026-71362
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili… |
9.1 | in the wild KEV 2026-09-24 | 2026-08-11 | the August authorisation flaw |
|
CVE-2025-54236
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerabil… |
9.1 | in the wild KEV 2025-10-24 | 2025-09-09 | SessionReaper |
|
CVE-2022-35698
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issu… |
10.0 | — | 2022-10-14 | tracked only |
|
CVE-2024-45115
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in pri… |
9.8 | — | 2024-10-10 | tracked only |
|
CVE-2020-9664
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary cod… |
9.8 | — | 2020-07-22 | tracked only |
|
CVE-2020-9632
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerabil… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9631
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerabil… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9630
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. S… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9585
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation … |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9583
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Succ… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9582
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Succ… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9580
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerabil… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9579
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerabil… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9578
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Succ… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-9576
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Succ… |
9.8 | — | 2020-06-26 | tracked only |
|
CVE-2020-3718
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploi… |
9.8 | — | 2020-01-29 | tracked only |
|
CVE-2020-3716
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability.… |
9.8 | — | 2020-01-29 | tracked only |
|
CVE-2019-8158
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to… |
9.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8149
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticate… |
9.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8144
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBu… |
9.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8136
An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated vers… |
9.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8135
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony fr… |
9.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8121
An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase levera… |
9.8 | — | 2019-11-05 | tracked only |
|
CVE-2019-7139
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This iss… |
9.8 | — | 2019-04-10 | tracked only |
|
CVE-2015-8707
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remo… |
9.8 | — | 2017-09-26 | tracked only |
|
CVE-2016-4010
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopp… |
9.8 | — | 2017-01-23 | tracked only |
|
CVE-2020-9691
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to ar… |
9.6 | — | 2020-07-29 | tracked only |
|
CVE-2026-76201
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerab… |
9.3 | — | 2026-09-08 | tracked only |
|
CVE-2026-76200
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerab… |
9.3 | — | 2026-09-08 | tracked only |
|
CVE-2026-48356
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context o… |
9.3 | — | 2026-07-14 | tracked only |
|
CVE-2026-48358
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the cu… |
9.1 | — | 2026-07-14 | tracked only |
|
CVE-2025-24434
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could… |
9.1 | — | 2025-02-11 | tracked only |
|
CVE-2024-34108
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbit… |
9.1 | — | 2024-06-13 | tracked only |
|
CVE-2024-20720
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co… |
9.1 | — | 2024-02-15 | tracked only |
|
CVE-2024-20719
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an… |
9.1 | — | 2024-02-15 | tracked only |
|
CVE-2022-24093
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this is… |
9.1 | — | 2023-09-12 | tracked only |
|
CVE-2021-36023
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets U… |
9.1 | — | 2023-09-06 | tracked only |
|
CVE-2023-38208
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Special Eleme… |
9.1 | — | 2023-08-09 | tracked only |
|
CVE-2023-29297
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Improper Neutralization of Special Elements … |
9.1 | — | 2023-06-15 | tracked only |
|
CVE-2021-21014
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitat… |
9.1 | — | 2021-02-11 | tracked only |
|
CVE-2021-21025
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successfu… |
9.1 | — | 2021-02-11 | tracked only |
|
CVE-2021-21024
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module… |
9.1 | — | 2021-02-11 | tracked only |
|
CVE-2021-21019
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploi… |
9.1 | — | 2021-02-11 | tracked only |
|
CVE-2021-21018
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation modul… |
9.1 | — | 2021-02-11 | tracked only |
|
CVE-2021-21016
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploi… |
9.1 | — | 2021-02-11 | tracked only |
|
CVE-2020-24407
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vuln… |
9.1 | — | 2020-11-09 | tracked only |
|
CVE-2024-39397
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability t… |
9.0 | — | 2024-08-14 | tracked only |
|
CVE-2024-20758
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in… |
9.0 | — | 2024-04-10 | tracked only |
|
CVE-2024-45148
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a s… |
8.8 | — | 2024-10-10 | tracked only |
|
CVE-2023-38218
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Aut… |
8.8 | — | 2023-10-13 | tracked only |
|
CVE-2022-42344
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An a… |
8.8 | — | 2022-10-20 | tracked only |
|
CVE-2022-34255
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that … |
8.8 | — | 2022-08-16 | tracked only |
|
CVE-2022-34254
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Rest… |
8.8 | — | 2022-08-16 | tracked only |
|
CVE-2015-6497
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) befor… |
8.8 | — | 2020-01-15 | tracked only |
|
CVE-2019-8159
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data m… |
8.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8154
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to… |
8.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8150
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to… |
8.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8137
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to… |
8.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8134
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with marketing privileges can execute arb… |
8.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8130
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with store manipulation privileges can ex… |
8.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8127
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to an acco… |
8.8 | — | 2019-11-05 | tracked only |
|
CVE-2019-8122
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user w… |
8.8 | — | 2019-11-05 | tracked only |
|
CVE-2019-8111
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage plugi… |
8.8 | — | 2019-11-05 | tracked only |
|
CVE-2019-8110
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage email… |
8.8 | — | 2019-11-05 | tracked only |
|
CVE-2019-8093
An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage file… |
8.8 | — | 2019-11-05 | tracked only |
|
CVE-2019-7885
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento … |
8.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7876
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user wi… |
8.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7871
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbitrary PHP… |
8.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7865
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 pr… |
8.8 | — | 2019-08-02 | tracked only |
|
CVE-2026-77111
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could… |
8.7 | — | 2026-09-08 | tracked only |
|
CVE-2026-48413
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts… |
8.7 | — | 2026-08-11 | tracked only |
|
CVE-2026-47994
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts… |
8.7 | — | 2026-07-14 | tracked only |
|
CVE-2026-34686
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vuln… |
8.7 | — | 2026-05-12 | tracked only |
|
CVE-2026-34653
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to … |
8.7 | — | 2026-05-12 | tracked only |
|
CVE-2026-21290
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vul… |
8.7 | — | 2026-03-11 | tracked only |
|
CVE-2025-49557
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a stored Cross-Site Scripting (XSS) vul… |
8.7 | — | 2025-08-12 | tracked only |
|
CVE-2025-24438
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24417
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24416
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24415
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24414
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24413
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24412
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24410
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
8.7 | — | 2025-02-11 | tracked only |
|
CVE-2023-38219
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-S… |
8.7 | — | 2023-10-13 | tracked only |
|
CVE-2026-77774
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulner… |
8.6 | — | 2026-09-08 | tracked only |
|
CVE-2026-77109
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili… |
8.6 | — | 2026-09-08 | tracked only |
|
CVE-2026-47988
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulner… |
8.6 | — | 2026-07-14 | tracked only |
|
CVE-2025-47110
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that c… |
8.4 | — | 2025-06-10 | tracked only |
|
CVE-2024-39402
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Comma… |
8.4 | — | 2024-08-14 | tracked only |
|
CVE-2024-39401
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Comma… |
8.4 | — | 2024-08-14 | tracked only |
|
CVE-2026-76202
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili… |
8.2 | — | 2026-09-08 | tracked only |
|
CVE-2026-47984
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulner… |
8.2 | — | 2026-07-14 | tracked only |
|
CVE-2025-43585
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could resul… |
8.2 | — | 2025-06-10 | tracked only |
|
CVE-2025-24409
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that coul… |
8.2 | — | 2025-02-11 | tracked only |
|
CVE-2024-34104
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Securi… |
8.2 | — | 2024-06-13 | tracked only |
|
CVE-2026-47995
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious script… |
8.1 | — | 2026-07-14 | tracked only |
|
CVE-2026-21361
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvu… |
8.1 | — | 2026-03-11 | tracked only |
|
CVE-2026-21284
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vul… |
8.1 | — | 2026-03-11 | tracked only |
|
CVE-2025-54264
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) Cro… |
8.1 | — | 2025-10-14 | tracked only |
|
CVE-2025-54263
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerabilit… |
8.1 | — | 2025-10-14 | tracked only |
|
CVE-2025-49555
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vul… |
8.1 | — | 2025-08-12 | tracked only |
|
CVE-2025-43586
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could resu… |
8.1 | — | 2025-06-10 | tracked only |
|
CVE-2025-24411
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could… |
8.1 | — | 2025-02-11 | tracked only |
|
CVE-2024-45116
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploite… |
8.1 | — | 2024-10-10 | tracked only |
|
CVE-2024-39400
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnera… |
8.1 | — | 2024-08-14 | tracked only |
|
CVE-2024-34103
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privile… |
8.1 | — | 2024-06-13 | tracked only |
|
CVE-2024-20759
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be… |
8.1 | — | 2024-04-10 | tracked only |
|
CVE-2021-21030
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer ad… |
8.1 | — | 2021-02-11 | tracked only |
|
CVE-2026-21311
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vul… |
8.0 | — | 2026-03-11 | tracked only |
|
CVE-2023-38250
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neut… |
8.0 | — | 2023-10-13 | tracked only |
|
CVE-2023-38249
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neut… |
8.0 | — | 2023-10-13 | tracked only |
|
CVE-2023-38221
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neut… |
8.0 | — | 2023-10-13 | tracked only |
|
CVE-2021-21015
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute sav… |
8.0 | — | 2021-02-11 | tracked only |
|
CVE-2020-15151
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surfac… |
8.0 | — | 2020-08-20 | tracked only |
|
CVE-2019-8109
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malici… |
8.0 | — | 2019-11-05 | tracked only |
|
CVE-2026-48414
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts… |
7.7 | — | 2026-08-11 | tracked only |
|
CVE-2024-49521
Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A … |
7.7 | — | 2024-11-12 | tracked only |
|
CVE-2024-39399
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('P… |
7.7 | — | 2024-08-14 | tracked only |
|
CVE-2026-77110
Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security… |
7.6 | — | 2026-09-08 | tracked only |
|
CVE-2026-48415
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could levera… |
7.6 | — | 2026-08-11 | tracked only |
|
CVE-2024-45117
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arb… |
7.6 | — | 2024-10-10 | tracked only |
|
CVE-2024-39403
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ab… |
7.6 | — | 2024-08-14 | tracked only |
|
CVE-2026-77108
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili… |
7.5 | — | 2026-09-08 | tracked only |
|
CVE-2026-48416
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulner… |
7.5 | — | 2026-08-11 | tracked only |
|
CVE-2026-34652
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party C… |
7.5 | — | 2026-05-12 | tracked only |
|
CVE-2026-34651
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vul… |
7.5 | — | 2026-05-12 | tracked only |
|
CVE-2026-34650
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vul… |
7.5 | — | 2026-05-12 | tracked only |
|
CVE-2026-34649
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vul… |
7.5 | — | 2026-05-12 | tracked only |
|
CVE-2026-34648
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vul… |
7.5 | — | 2026-05-12 | tracked only |
|
CVE-2026-34646
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability… |
7.5 | — | 2026-05-12 | tracked only |
|
CVE-2026-34645
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability… |
7.5 | — | 2026-05-12 | tracked only |
|
CVE-2026-21309
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerabilit… |
7.5 | — | 2026-03-11 | tracked only |
|
CVE-2026-21289
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerabilit… |
7.5 | — | 2026-03-11 | tracked only |
|
CVE-2025-49556
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerabilit… |
7.5 | — | 2025-08-12 | tracked only |
|
CVE-2025-49554
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerabil… |
7.5 | — | 2025-08-12 | tracked only |
|
CVE-2025-24406
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricte… |
7.5 | — | 2025-02-11 | tracked only |
|
CVE-2023-38220
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Auth… |
7.5 | — | 2023-10-13 | tracked only |
|
CVE-2023-38207
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection)… |
7.5 | — | 2023-08-09 | tracked only |
|
CVE-2023-22248
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that … |
7.5 | — | 2023-06-15 | tracked only |
|
CVE-2023-22247
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file sy… |
7.5 | — | 2023-03-27 | tracked only |
|
CVE-2022-34256
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that c… |
7.5 | — | 2022-08-16 | tracked only |
|
CVE-2021-28583
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability… |
7.5 | — | 2021-06-28 | tracked only |
|
CVE-2020-9591
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation … |
7.5 | — | 2020-06-26 | tracked only |
|
CVE-2020-9587
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. … |
7.5 | — | 2020-06-26 | tracked only |
|
CVE-2020-3719
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploit… |
7.5 | — | 2020-01-29 | tracked only |
|
CVE-2019-8155
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access t… |
7.5 | — | 2019-11-06 | tracked only |
|
CVE-2019-8116
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticate… |
7.5 | — | 2019-11-05 | tracked only |
|
CVE-2019-8112
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can bypass the email c… |
7.5 | — | 2019-11-05 | tracked only |
|
CVE-2019-7951
An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A SOAP web service endpoi… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7950
An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7928
A denial-of-service (DoS) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. By abusing insufficien… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7915
A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Under certain conditions, an… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7886
A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to g… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7861
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prio… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7860
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7859
A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in … |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7858
A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information w… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7854
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to u… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7849
A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.… |
7.5 | — | 2019-08-02 | tracked only |
|
CVE-2026-34647
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vul… |
7.4 | — | 2026-05-12 | tracked only |
|
CVE-2024-39398
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulne… |
7.4 | — | 2024-08-14 | tracked only |
|
CVE-2019-7890
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, … |
7.3 | — | 2019-08-02 | tracked only |
|
CVE-2026-47992
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbi… |
7.2 | — | 2026-07-14 | tracked only |
|
CVE-2024-34110
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that… |
7.2 | — | 2024-06-13 | tracked only |
|
CVE-2024-34109
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbit… |
7.2 | — | 2024-06-13 | tracked only |
|
CVE-2021-36036
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento'… |
7.2 | — | 2023-09-06 | tracked only |
|
CVE-2021-36021
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CM… |
7.2 | — | 2023-09-06 | tracked only |
|
CVE-2022-34253
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets … |
7.2 | — | 2022-08-16 | tracked only |
|
CVE-2020-9588
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulner… |
7.2 | — | 2020-06-26 | tracked only |
|
CVE-2019-8156
A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with … |
7.2 | — | 2019-11-06 | tracked only |
|
CVE-2019-8231
In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary co… |
7.2 | — | 2019-11-06 | tracked only |
|
CVE-2019-8230
In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute ar… |
7.2 | — | 2019-11-06 | tracked only |
|
CVE-2019-8229
In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbit… |
7.2 | — | 2019-11-06 | tracked only |
|
CVE-2019-8151
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privile… |
7.2 | — | 2019-11-06 | tracked only |
|
CVE-2019-8141
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user w… |
7.2 | — | 2019-11-06 | tracked only |
|
CVE-2019-8125
A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x. An authenticated admin user can modify configuration parameters via craf… |
7.2 | — | 2019-11-05 | tracked only |
|
CVE-2019-8119
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated admin … |
7.2 | — | 2019-11-05 | tracked only |
|
CVE-2019-8114
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.… |
7.2 | — | 2019-11-05 | tracked only |
|
CVE-2019-8091
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user with privileges to access product attrib… |
7.2 | — | 2019-11-05 | tracked only |
|
CVE-2019-7942
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user wi… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7932
A remote code execution vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Ma… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7930
A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with ad… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7923
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7913
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7912
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authen… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7911
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior … |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7903
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user wi… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7896
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user wi… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7895
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user wi… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2019-7892
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user wi… |
7.2 | — | 2019-08-02 | tracked only |
|
CVE-2020-24400
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulne… |
7.1 | — | 2020-11-09 | tracked only |
|
CVE-2021-28556
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mag… |
6.9 | — | 2021-06-28 | tracked only |
|
CVE-2026-47996
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploi… |
6.8 | — | 2026-07-14 | tracked only |
|
CVE-2026-21360
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to… |
6.8 | — | 2026-03-11 | tracked only |
|
CVE-2024-39406
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('P… |
6.8 | — | 2024-08-14 | tracked only |
|
CVE-2023-26366
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Server-Side Re… |
6.8 | — | 2023-10-13 | tracked only |
|
CVE-2019-8232
In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with a… |
6.6 | — | 2019-11-06 | tracked only |
|
CVE-2026-48411
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could… |
6.5 | — | 2026-08-11 | tracked only |
|
CVE-2025-54267
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerabilit… |
6.5 | — | 2025-10-14 | tracked only |
|
CVE-2025-24427
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could… |
6.5 | — | 2025-02-11 | tracked only |
|
CVE-2025-24408
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could re… |
6.5 | — | 2025-02-11 | tracked only |
|
CVE-2024-45132
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Priv… |
6.5 | — | 2024-10-10 | tracked only |
|
CVE-2024-45118
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a S… |
6.5 | — | 2024-10-10 | tracked only |
|
CVE-2024-34111
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to… |
6.5 | — | 2024-06-13 | tracked only |
|
CVE-2023-38209
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerability th… |
6.5 | — | 2023-08-09 | tracked only |
|
CVE-2023-29289
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an XML Injection vulnerability. An attacker wi… |
6.5 | — | 2023-06-15 | tracked only |
|
CVE-2021-39864
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerabili… |
6.5 | — | 2021-10-15 | tracked only |
|
CVE-2021-28567
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the cust… |
6.5 | — | 2021-09-08 | tracked only |
|
CVE-2021-28563
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Crea… |
6.5 | — | 2021-06-28 | tracked only |
|
CVE-2020-24401
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned unde… |
6.5 | — | 2020-11-09 | tracked only |
|
CVE-2020-9692
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitr… |
6.5 | — | 2020-07-29 | tracked only |
|
CVE-2020-9689
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code exe… |
6.5 | — | 2020-07-29 | tracked only |
|
CVE-2019-8143
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templ… |
6.5 | — | 2019-11-06 | tracked only |
|
CVE-2019-8133
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with privileges to generate sitemaps ca… |
6.5 | — | 2019-11-06 | tracked only |
|
CVE-2019-8108
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated … |
6.5 | — | 2019-11-05 | tracked only |
|
CVE-2019-8107
An arbitrary file deletion vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with export dat… |
6.5 | — | 2019-11-05 | tracked only |
|
CVE-2019-8090
An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated use… |
6.5 | — | 2019-11-05 | tracked only |
|
CVE-2019-8235
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authe… |
6.5 | — | 2019-10-30 | tracked only |
|
CVE-2019-7947
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior… |
6.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7904
Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable a low-pr… |
6.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7889
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 p… |
6.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7888
An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user … |
6.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7874
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in … |
6.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7872
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to… |
6.5 | — | 2019-08-02 | tracked only |
|
CVE-2019-7851
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data… |
6.5 | — | 2019-08-02 | tracked only |
|
CVE-2018-5301
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address b… |
6.5 | — | 2018-01-08 | tracked only |
|
CVE-2015-3458
The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not res… |
6.5 | — | 2015-04-29 | tracked only |
|
CVE-2015-1399
PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and En… |
6.5 | — | 2015-04-29 | tracked only |
|
CVE-2015-1398
Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users … |
6.5 | — | 2015-04-29 | tracked only |
|
CVE-2015-1397
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise… |
6.5 | — | 2015-04-29 | tracked only |
|
CVE-2026-48000
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct … |
6.1 | — | 2026-07-14 | tracked only |
|
CVE-2024-45123
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attac… |
6.1 | — | 2024-10-10 | tracked only |
|
CVE-2022-34257
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerabil… |
6.1 | — | 2022-08-16 | tracked only |
|
CVE-2020-24408
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file… |
6.1 | — | 2020-10-16 | tracked only |
|
CVE-2020-9665
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensit… |
6.1 | — | 2020-07-22 | tracked only |
|
CVE-2020-9581
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerabi… |
6.1 | — | 2020-06-26 | tracked only |
|
CVE-2020-9577
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerabi… |
6.1 | — | 2020-06-26 | tracked only |
|
CVE-2020-3758
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Succe… |
6.1 | — | 2020-01-29 | tracked only |
|
CVE-2020-3715
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Succe… |
6.1 | — | 2020-01-29 | tracked only |
|
CVE-2019-8233
In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of the sanit… |
6.1 | — | 2019-11-06 | tracked only |
|
CVE-2019-8153
A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitat… |
6.1 | — | 2019-11-06 | tracked only |
|
CVE-2019-7939
A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento … |
6.1 | — | 2019-08-02 | tracked only |
|
CVE-2019-7877
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
6.1 | — | 2019-08-02 | tracked only |
|
CVE-2016-10704
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka… |
6.1 | — | 2017-12-30 | tracked only |
|
CVE-2014-9758
Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1. |
6.1 | — | 2017-09-20 | tracked only |
|
CVE-2026-47998
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulner… |
5.9 | — | 2026-07-14 | tracked only |
|
CVE-2026-47997
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulner… |
5.9 | — | 2026-07-14 | tracked only |
|
CVE-2025-54265
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerabilit… |
5.9 | — | 2025-10-14 | tracked only |
|
CVE-2025-49558
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Ra… |
5.9 | — | 2025-08-12 | tracked only |
|
CVE-2021-21032
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of t… |
5.6 | — | 2021-02-11 | tracked only |
|
CVE-2021-21031
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation coul… |
5.6 | — | 2021-02-11 | tracked only |
|
CVE-2026-21294
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vu… |
5.5 | — | 2026-03-11 | tracked only |
|
CVE-2026-21293
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vu… |
5.5 | — | 2026-03-11 | tracked only |
|
CVE-2026-48371
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts… |
5.4 | — | 2026-07-14 | tracked only |
|
CVE-2026-21292
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vul… |
5.4 | — | 2026-03-11 | tracked only |
|
CVE-2025-24437
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could… |
5.4 | — | 2025-02-11 | tracked only |
|
CVE-2025-24428
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t… |
5.4 | — | 2025-02-11 | tracked only |
|
CVE-2024-45131
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Se… |
5.4 | — | 2024-10-10 | tracked only |
|
CVE-2024-45128
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Se… |
5.4 | — | 2024-10-10 | tracked only |
|
CVE-2024-39418
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
5.4 | — | 2024-08-14 | tracked only |
|
CVE-2024-20717
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a … |
5.4 | — | 2024-02-15 | tracked only |
|
CVE-2021-28584
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store … |
5.4 | — | 2021-06-28 | tracked only |
|
CVE-2020-9584
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerabi… |
5.4 | — | 2020-06-26 | tracked only |
|
CVE-2019-8157
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can ma… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8145
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can in… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8132
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can cr… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8152
A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8147
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can in… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8146
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can in… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8142
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can in… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8139
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript cod… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8138
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can ex… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8131
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can in… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8129
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can ex… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8128
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can ex… |
5.4 | — | 2019-11-06 | tracked only |
|
CVE-2019-8120
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenti… |
5.4 | — | 2019-11-05 | tracked only |
|
CVE-2019-8117
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can in… |
5.4 | — | 2019-11-05 | tracked only |
|
CVE-2019-8092
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can… |
5.4 | — | 2019-11-05 | tracked only |
|
CVE-2019-7945
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.… |
5.4 | — | 2019-08-02 | tracked only |
|
CVE-2019-7944
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.… |
5.4 | — | 2019-08-02 | tracked only |
|
CVE-2019-7921
A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior … |
5.4 | — | 2019-08-02 | tracked only |
|
CVE-2019-7882
A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Mag… |
5.4 | — | 2019-08-02 | tracked only |
|
CVE-2019-7881
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploit… |
5.4 | — | 2019-08-02 | tracked only |
|
CVE-2026-34654
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party C… |
5.3 | — | 2026-05-12 | tracked only |
|
CVE-2026-21310
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerabil… |
5.3 | — | 2026-03-11 | tracked only |
|
CVE-2026-21286
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerabilit… |
5.3 | — | 2026-03-11 | tracked only |
|
CVE-2026-21282
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerabil… |
5.3 | — | 2026-03-11 | tracked only |
|
CVE-2025-49559
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to… |
5.3 | — | 2025-08-12 | tracked only |
|
CVE-2025-27206
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could resu… |
5.3 | — | 2025-06-10 | tracked only |
|
CVE-2025-27191
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could… |
5.3 | — | 2025-04-08 | tracked only |
|
CVE-2025-27190
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could… |
5.3 | — | 2025-04-08 | tracked only |
|
CVE-2025-24425
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could res… |
5.3 | — | 2025-02-11 | tracked only |
|
CVE-2024-45124
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a S… |
5.3 | — | 2024-10-10 | tracked only |
|
CVE-2024-34107
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Secur… |
5.3 | — | 2024-06-13 | tracked only |
|
CVE-2024-34106
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a secur… |
5.3 | — | 2024-06-13 | tracked only |
|
CVE-2023-38251
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled R… |
5.3 | — | 2023-10-13 | tracked only |
|
CVE-2023-29290
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that … |
5.3 | — | 2023-06-15 | tracked only |
|
CVE-2023-29287
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability that cou… |
5.3 | — | 2023-06-15 | tracked only |
|
CVE-2023-22250
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Sec… |
5.3 | — | 2023-03-27 | tracked only |
|
CVE-2022-35689
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Securi… |
5.3 | — | 2022-10-14 | tracked only |
|
CVE-2022-35692
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that … |
5.3 | — | 2022-08-19 | tracked only |
|
CVE-2022-34259
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that … |
5.3 | — | 2022-08-16 | tracked only |
|
CVE-2021-28585
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New… |
5.3 | — | 2021-06-28 | tracked only |
|
CVE-2021-21026
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrati… |
5.3 | — | 2021-02-11 | tracked only |
|
CVE-2021-21022
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the prod… |
5.3 | — | 2021-02-11 | tracked only |
|
CVE-2021-21020
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as… |
5.3 | — | 2021-02-11 | tracked only |
|
CVE-2020-3717
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploit… |
5.3 | — | 2020-01-29 | tracked only |
|
CVE-2019-8123
An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2… |
5.3 | — | 2019-11-05 | tracked only |
|
CVE-2019-8118
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for … |
5.3 | — | 2019-11-05 | tracked only |
|
CVE-2019-8113
Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code … |
5.3 | — | 2019-11-05 | tracked only |
|
CVE-2019-7899
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Co… |
5.3 | — | 2019-08-02 | tracked only |
|
CVE-2019-7898
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior t… |
5.3 | — | 2019-08-02 | tracked only |
|
CVE-2019-7864
An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prio… |
5.3 | — | 2019-08-02 | tracked only |
|
CVE-2019-7855
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to disc… |
5.3 | — | 2019-08-02 | tracked only |
|
CVE-2019-7852
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file p… |
5.3 | — | 2019-08-02 | tracked only |
|
CVE-2016-2212
The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition before 1.14.2… |
5.3 | — | 2016-04-15 | tracked only |
|
CVE-2015-3457
Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter. |
5.0 | — | 2015-04-29 | tracked only |
|
CVE-2024-45119
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could l… |
4.9 | — | 2024-10-10 | tracked only |
|
CVE-2024-20716
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an app… |
4.9 | — | 2024-02-15 | tracked only |
|
CVE-2023-26367
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Inpu… |
4.9 | — | 2023-10-13 | tracked only |
|
CVE-2023-29292
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerabi… |
4.9 | — | 2023-06-15 | tracked only |
|
CVE-2023-29291
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerabi… |
4.9 | — | 2023-06-15 | tracked only |
|
CVE-2020-24402
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability coul… |
4.9 | — | 2020-11-09 | tracked only |
|
CVE-2019-8140
An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can mani… |
4.9 | — | 2019-11-06 | tracked only |
|
CVE-2019-8126
An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft do… |
4.9 | — | 2019-11-05 | tracked only |
|
CVE-2019-8124
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure … |
4.9 | — | 2019-11-05 | tracked only |
|
CVE-2019-7929
An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user wit… |
4.9 | — | 2019-08-02 | tracked only |
|
CVE-2019-7925
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This … |
4.9 | — | 2019-08-02 | tracked only |
|
CVE-2026-47999
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious script… |
4.8 | — | 2026-07-14 | tracked only |
|
CVE-2026-34658
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vuln… |
4.8 | — | 2026-05-12 | tracked only |
|
CVE-2026-34655
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vuln… |
4.8 | — | 2026-05-12 | tracked only |
|
CVE-2026-21291
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vul… |
4.8 | — | 2026-03-11 | tracked only |
|
CVE-2025-54266
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vul… |
4.8 | — | 2025-10-14 | tracked only |
|
CVE-2024-45127
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be a… |
4.8 | — | 2024-10-10 | tracked only |
|
CVE-2024-34105
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abuse… |
4.8 | — | 2024-06-13 | tracked only |
|
CVE-2023-22249
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abu… |
4.8 | — | 2023-03-27 | tracked only |
|
CVE-2022-34258
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerabil… |
4.8 | — | 2022-08-16 | tracked only |
|
CVE-2021-21029
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file… |
4.8 | — | 2021-02-11 | tracked only |
|
CVE-2021-21023
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the adm… |
4.8 | — | 2021-02-11 | tracked only |
|
CVE-2019-8228
in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code … |
4.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8227
In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code … |
4.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8148
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScri… |
4.8 | — | 2019-11-06 | tracked only |
|
CVE-2019-8115
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin us… |
4.8 | — | 2019-11-05 | tracked only |
|
CVE-2019-7940
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magent… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7938
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magent… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7937
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7936
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7935
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magent… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7934
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magent… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7927
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7926
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7909
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magent… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7908
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7897
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magent… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7887
A reflected cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Mag… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7880
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7875
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magent… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7869
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7868
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7867
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7866
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7863
A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7862
A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2019-7853
A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be expl… |
4.8 | — | 2019-08-02 | tracked only |
|
CVE-2026-21359
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerabilit… |
4.7 | — | 2026-03-11 | tracked only |
|
CVE-2026-34656
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability … |
4.3 | — | 2026-05-12 | tracked only |
|
CVE-2026-21297
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerabilit… |
4.3 | — | 2026-03-11 | tracked only |
|
CVE-2026-21296
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerabilit… |
4.3 | — | 2026-03-11 | tracked only |
|
CVE-2026-21285
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerabilit… |
4.3 | — | 2026-03-11 | tracked only |
|
CVE-2025-49550
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could resu… |
4.3 | — | 2025-06-25 | tracked only |
|
CVE-2025-27188
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could … |
4.3 | — | 2025-04-08 | tracked only |
|
CVE-2025-24436
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could… |
4.3 | — | 2025-02-11 | tracked only |
|
CVE-2025-24435
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could… |
4.3 | — | 2025-02-11 | tracked only |
|
CVE-2025-24421
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could… |
4.3 | — | 2025-02-11 | tracked only |
|
CVE-2024-45130
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a S… |
4.3 | — | 2024-10-10 | tracked only |
|
CVE-2024-45129
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Pri… |
4.3 | — | 2024-10-10 | tracked only |
|
CVE-2024-45125
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a s… |
4.3 | — | 2024-10-10 | tracked only |
|
CVE-2024-45122
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a S… |
4.3 | — | 2024-10-10 | tracked only |
|
CVE-2024-45121
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a S… |
4.3 | — | 2024-10-10 | tracked only |
|
CVE-2024-39419
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39417
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39416
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39415
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39414
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39413
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39412
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39411
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39410
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39409
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39408
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39407
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39405
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-39404
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Sec… |
4.3 | — | 2024-08-14 | tracked only |
|
CVE-2024-20718
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Sec… |
4.3 | — | 2024-02-15 | tracked only |
|
CVE-2023-29296
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that … |
4.3 | — | 2023-06-15 | tracked only |
|
CVE-2023-29295
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that … |
4.3 | — | 2023-06-15 | tracked only |
|
CVE-2023-29294
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that cou… |
4.3 | — | 2023-06-15 | tracked only |
|
CVE-2023-29288
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that … |
4.3 | — | 2023-06-15 | tracked only |
|
CVE-2023-22251
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenti… |
4.3 | — | 2023-03-27 | tracked only |
|
CVE-2021-21027
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via th… |
4.3 | — | 2021-02-11 | tracked only |
|
CVE-2020-24405
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability coul… |
4.3 | — | 2020-11-09 | tracked only |
|
CVE-2019-7873
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in … |
4.3 | — | 2019-08-02 | tracked only |
|
CVE-2019-7857
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to… |
4.3 | — | 2019-08-02 | tracked only |
|
CVE-2020-9690
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to si… |
4.2 | — | 2020-07-29 | tracked only |
|
CVE-2026-48001
Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on cond… |
3.7 | — | 2026-07-14 | tracked only |
|
CVE-2025-24432
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition… |
3.7 | — | 2025-02-11 | tracked only |
|
CVE-2025-24430
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition… |
3.7 | — | 2025-02-11 | tracked only |
|
CVE-2021-28566
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when upload… |
3.7 | — | 2021-09-08 | tracked only |
|
CVE-2020-24406
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the install… |
3.7 | — | 2020-11-09 | tracked only |
|
CVE-2025-24429
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could… |
3.5 | — | 2025-02-11 | tracked only |
|
CVE-2026-34685
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Input Validation vulnerabili… |
3.4 | — | 2026-05-12 | tracked only |
|
CVE-2026-21295
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('O… |
3.1 | — | 2026-03-11 | tracked only |
|
CVE-2024-45120
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability… |
3.1 | — | 2024-10-10 | tracked only |
|
CVE-2026-48412
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could expl… |
2.7 | — | 2026-08-11 | tracked only |
|
CVE-2025-49549
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could resu… |
2.7 | — | 2025-06-25 | tracked only |
|
CVE-2025-27192
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerabili… |
2.7 | — | 2025-04-08 | tracked only |
|
CVE-2024-45149
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a S… |
2.7 | — | 2024-10-10 | tracked only |
|
CVE-2024-45135
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a S… |
2.7 | — | 2024-10-10 | tracked only |
|
CVE-2024-45134
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a secu… |
2.7 | — | 2024-10-10 | tracked only |
|
CVE-2024-45133
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a secu… |
2.7 | — | 2024-10-10 | tracked only |
|
CVE-2023-29293
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability tha… |
2.7 | — | 2023-06-15 | tracked only |
|
CVE-2020-24404
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability … |
2.7 | — | 2020-11-09 | tracked only |
|
CVE-2020-24403
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerabilit… |
2.7 | — | 2020-11-09 | tracked only |
Most of what is here is long fixed — the index goes back years, and an advisory against a release nobody runs any more is history rather than a risk. That is precisely why a report names the handful we can actually place on your store instead of listing all of these.
From intelligence vault 2026.09.6, released 2026-09-25. Index last synced 9 hours ago.