📦 Commerce

by Adobe

🔍 What is Commerce?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54236

CRITICAL CVSS 9.1 Sep 9, 2025

CVE-2025-54236 is an improper input validation vulnerability in Adobe Commerce (Magento) that allows unauthenticated attackers to achieve session takeover. This enables attackers to hijack user sessio...

CVE-2025-24434

CRITICAL CVSS 9.1 Feb 11, 2025

CVE-2025-24434 is an incorrect authorization vulnerability in Adobe Commerce that allows attackers to bypass security controls and escalate privileges without user interaction. This affects Adobe Comm...

CVE-2024-45115

CRITICAL CVSS 9.8 Oct 10, 2024

CVE-2024-45115 is an improper authentication vulnerability in Adobe Commerce that allows attackers to bypass authentication mechanisms and gain elevated privileges without user interaction. This affec...

CVE-2024-39397

CRITICAL CVSS 9.0 Aug 14, 2024

This vulnerability allows attackers to upload malicious files to Adobe Commerce servers, potentially leading to arbitrary code execution. It affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p...

CVE-2024-34108

CRITICAL CVSS 9.1 Jun 13, 2024

This CVE describes an Improper Input Validation vulnerability in Adobe Commerce that allows authenticated users with admin privileges to execute arbitrary code on affected systems. The vulnerability a...

CVE-2024-34102

CRITICAL CVSS 9.8 Jun 13, 2024

This critical XXE vulnerability in Adobe Commerce allows unauthenticated attackers to execute arbitrary code by sending malicious XML documents. It affects Adobe Commerce (formerly Magento) versions 2...

CVE-2024-20758

CRITICAL CVSS 9.0 Apr 10, 2024

This CVE describes an Improper Input Validation vulnerability in Adobe Commerce that allows attackers to execute arbitrary code on the underlying filesystem. The vulnerability affects Adobe Commerce v...

CVE-2024-20719

CRITICAL CVSS 9.1 Feb 15, 2024

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows an authenticated admin attacker to inject malicious JavaScript into admin pages. When other admin users view these pages, ...

CVE-2022-24093

CRITICAL CVSS 9.1 Sep 12, 2023

CVE-2022-24093 is an improper input validation vulnerability in Adobe Commerce (formerly Magento) that allows authenticated attackers to execute arbitrary code on affected systems. This affects Adobe ...

CVE-2023-38208

CRITICAL CVSS 9.1 Aug 9, 2023

This CVE describes an OS command injection vulnerability in Adobe Commerce (formerly Magento) that allows authenticated administrators to execute arbitrary commands on the server. Attackers with admin...

CVE-2023-29297

CRITICAL CVSS 9.1 Jun 15, 2023

This vulnerability allows authenticated admin users in Adobe Commerce to execute arbitrary code through improper template engine neutralization. It affects Adobe Commerce versions 2.4.6 and earlier, 2...

CVE-2022-24086

CRITICAL CVSS 9.8 Feb 16, 2022

CVE-2022-24086 is a critical improper input validation vulnerability in Adobe Commerce (formerly Magento) that allows unauthenticated attackers to execute arbitrary code during checkout. This affects ...

CVE-2025-54263

HIGH CVSS 8.1 Oct 14, 2025

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security controls and maintain unauthorized access without user interaction. This affects Ado...

CVE-2025-49556

HIGH CVSS 7.5 Aug 12, 2025

Adobe Commerce has an incorrect authorization vulnerability that allows attackers to bypass security measures and gain unauthorized read access to sensitive data. This affects Adobe Commerce versions ...

CVE-2025-49554

HIGH CVSS 7.5 Aug 12, 2025

Adobe Commerce has an improper input validation vulnerability (CWE-20) that allows unauthenticated attackers to cause denial-of-service by sending specially crafted input. This affects Adobe Commerce ...

CVE-2025-43585

HIGH CVSS 8.2 Jun 10, 2025

Adobe Commerce has an improper authorization vulnerability that allows attackers to bypass security measures and gain unauthorized access. This affects Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p...

CVE-2025-24438

HIGH CVSS 8.7 Feb 11, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing the...

CVE-2025-24416

HIGH CVSS 8.7 Feb 11, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing the...

CVE-2025-24417

HIGH CVSS 8.7 Feb 11, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious scripts into form fields. When victims browse pages containing these fields, the...

CVE-2025-24411

HIGH CVSS 8.1 Feb 11, 2025

Adobe Commerce has an improper access control vulnerability that allows low-privileged attackers to bypass security measures and gain unauthorized access to sensitive data or modify content. This affe...

CVE-2025-24410

HIGH CVSS 8.7 Feb 11, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing the...

CVE-2025-24412

HIGH CVSS 8.7 Feb 11, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing the...

CVE-2025-24413

HIGH CVSS 8.7 Feb 11, 2025

A stored cross-site scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious scripts into vulnerable form fields. When victims browse pages containing these ...

CVE-2025-24414

HIGH CVSS 8.7 Feb 11, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing the...

CVE-2025-24415

HIGH CVSS 8.7 Feb 11, 2025

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing the...

CVE-2025-24406

HIGH CVSS 7.5 Feb 11, 2025

This CVE describes a path traversal vulnerability in Adobe Commerce that allows unauthenticated attackers to modify files outside restricted directories. This security feature bypass affects Adobe Com...

CVE-2025-24409

HIGH CVSS 8.2 Feb 11, 2025

This CVE describes an incorrect authorization vulnerability in Adobe Commerce that allows attackers to bypass security measures and gain unauthorized access to sensitive data. Affected versions includ...

CVE-2024-49521

HIGH CVSS 7.7 Nov 12, 2024

Adobe Commerce versions 3.2.5 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability that allows low-privileged attackers to send crafted requests from the vulnerable server to interna...

CVE-2024-45148

HIGH CVSS 8.8 Oct 10, 2024

CVE-2024-45148 is an improper authentication vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security features and gain unauthorized access without valid credentials. Th...

CVE-2024-45117

HIGH CVSS 7.6 Oct 10, 2024

This CVE describes an Improper Input Validation vulnerability in Adobe Commerce that allows authenticated admin attackers to read arbitrary files from the server filesystem using PHP filter chain tech...

CVE-2024-39401

HIGH CVSS 8.4 Aug 14, 2024

This CVE describes an OS command injection vulnerability in Adobe Commerce that allows authenticated admin users to execute arbitrary commands on the server. The vulnerability requires user interactio...

CVE-2024-39403

HIGH CVSS 7.6 Aug 14, 2024

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse pages containing the...

CVE-2024-39399

HIGH CVSS 7.7 Aug 14, 2024

CVE-2024-39399 is a path traversal vulnerability in Adobe Commerce that allows low-privileged attackers to read arbitrary files from the server's filesystem without user interaction. This affects Adob...

CVE-2024-34110

HIGH CVSS 7.2 Jun 13, 2024

This vulnerability allows high-privilege attackers to upload malicious files to Adobe Commerce systems, potentially leading to arbitrary code execution. Affected versions include Adobe Commerce 2.4.7,...

CVE-2024-34104

HIGH CVSS 8.2 Jun 13, 2024

This CVE describes an Improper Authorization vulnerability in Adobe Commerce that allows attackers to bypass security measures without user interaction. Affected systems include Adobe Commerce version...

CVE-2023-38249

HIGH CVSS 8.0 Oct 13, 2023

This SQL injection vulnerability in Adobe Commerce allows authenticated attackers with admin privileges to execute arbitrary code on affected systems. It affects multiple Adobe Commerce versions up to...

CVE-2023-38218

HIGH CVSS 8.8 Oct 13, 2023

This CVE-2023-38218 vulnerability in Adobe Commerce allows authenticated attackers to bypass authorization controls, potentially exposing sensitive information and escalating privileges. It affects mu...

CVE-2023-38220

HIGH CVSS 7.5 Oct 13, 2023

CVE-2023-38220 is an improper authorization vulnerability in Adobe Commerce (formerly Magento) that allows attackers to bypass security controls and access unauthorized data without user interaction. ...

CVE-2023-22248

HIGH CVSS 7.5 Jun 15, 2023

This CVE describes an incorrect authorization vulnerability in Adobe Commerce that allows attackers to bypass security features and access other users' data without requiring any user interaction. It ...

CVE-2023-22247

HIGH CVSS 7.5 Mar 27, 2023

CVE-2023-22247 is an XML injection vulnerability in Adobe Commerce that allows unauthenticated attackers to read arbitrary files from the server. This affects Adobe Commerce versions 2.4.4-p2 and earl...

CVE-2025-54265

MEDIUM CVSS 5.9 Oct 14, 2025

Adobe Commerce (Magento) versions 2.4.9-alpha2 through 2.4.4-p15 and earlier contain an incorrect authorization vulnerability (CWE-863) that allows attackers to bypass security controls and gain unaut...

CVE-2025-54266

MEDIUM CVSS 4.8 Oct 14, 2025

A stored cross-site scripting (XSS) vulnerability in Adobe Commerce allows high-privileged attackers to inject malicious JavaScript into vulnerable form fields. When victims browse to pages containing...

CVE-2025-54267

MEDIUM CVSS 6.5 Oct 14, 2025

This CVE describes an incorrect authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security controls and gain unauthorized elevated privileges. The vulnerabil...

CVE-2025-49558

MEDIUM CVSS 5.9 Aug 12, 2025

This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Commerce that allows attackers to bypass security features and gain unauthorized write access. The vulnera...

CVE-2025-49559

MEDIUM CVSS 5.3 Aug 12, 2025

This CVE describes a path traversal vulnerability in Adobe Commerce that allows attackers to bypass security restrictions and modify limited data without user interaction. Affected versions include Ad...

CVE-2025-49550

MEDIUM CVSS 4.3 Jun 25, 2025

Adobe Commerce has an incorrect authorization vulnerability (CWE-863) that allows attackers to bypass security features and gain limited unauthorized access. This affects versions 2.4.8, 2.4.7-p5, 2.4...

CVE-2025-27206

MEDIUM CVSS 5.3 Jun 10, 2025

This CVE describes an Improper Access Control vulnerability in Adobe Commerce that allows attackers to bypass security measures and gain limited write access without user interaction. Affected version...

CVE-2025-27188

MEDIUM CVSS 4.3 Apr 8, 2025

CVE-2025-27188 is an improper authorization vulnerability in Adobe Commerce that allows attackers to bypass security controls and escalate privileges without user interaction. This affects Adobe Comme...

CVE-2025-27190

MEDIUM CVSS 5.3 Apr 8, 2025

This CVE describes an Improper Access Control vulnerability in Adobe Commerce that allows attackers to bypass security measures and gain unauthorized access without user interaction. It affects Adobe ...

CVE-2025-24436

MEDIUM CVSS 4.3 Feb 11, 2025

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security features and view select information without user interaction. This affects Adobe Co...

CVE-2025-24427

MEDIUM CVSS 6.5 Feb 11, 2025

CVE-2025-24427 is an improper access control vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures and gain unauthorized write access without user interactio...

CVE-2025-24421

MEDIUM CVSS 4.3 Feb 11, 2025

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security features and read select data without user interaction. This affects Adobe Commerce ...

CVE-2025-24425

MEDIUM CVSS 5.3 Feb 11, 2025

This CVE describes a business logic error in Adobe Commerce that allows attackers to bypass security features and modify limited data without user interaction. Affected versions include Adobe Commerce...

CVE-2025-24408

MEDIUM CVSS 6.5 Feb 11, 2025

Adobe Commerce has an information exposure vulnerability that allows low-privileged attackers to access sensitive data without user interaction. This could lead to privilege escalation by exposing cre...

CVE-2024-45132

MEDIUM CVSS 6.5 Oct 10, 2024

CVE-2024-45132 is an improper authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security controls and escalate privileges. This affects Adobe Commerce versio...

CVE-2024-45128

MEDIUM CVSS 5.4 Oct 10, 2024

This CVE describes an Improper Authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures. The vulnerability affects Adobe Commerce versions 2.4.7-p...

CVE-2024-45130

MEDIUM CVSS 4.3 Oct 10, 2024

This CVE describes an Improper Access Control vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures. Affected versions include Adobe Commerce 2.4.7-p2, 2.4.6...

CVE-2024-45123

MEDIUM CVSS 6.1 Oct 10, 2024

This reflected Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows attackers to execute malicious JavaScript in victims' browsers by tricking them into visiting specially crafted URLs. T...

CVE-2024-45125

MEDIUM CVSS 4.3 Oct 10, 2024

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security features and potentially modify data. This affects Adobe Commerce versions 2.4.7-p2,...

CVE-2024-45119

MEDIUM CVSS 4.9 Oct 10, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Adobe Commerce that allows authenticated administrators to force the application to make arbitrary HTTP requests to internal sy...

CVE-2024-45121

MEDIUM CVSS 4.3 Oct 10, 2024

CVE-2024-45121 is an Improper Access Control vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security features. This affects Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, ...

CVE-2024-39419

MEDIUM CVSS 4.3 Aug 14, 2024

CVE-2024-39419 is an improper authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures and modify minor information without user interaction. This...

CVE-2024-39415

MEDIUM CVSS 4.3 Aug 14, 2024

CVE-2024-39415 is an improper authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures and access minor information without user interaction. This...

CVE-2024-39417

MEDIUM CVSS 4.3 Aug 14, 2024

CVE-2024-39417 is an improper authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures and access minor information without user interaction. This...

CVE-2024-39411

MEDIUM CVSS 4.3 Aug 14, 2024

CVE-2024-39411 is an improper authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures and access minor information without user interaction. This...

CVE-2024-39413

MEDIUM CVSS 4.3 Aug 14, 2024

Adobe Commerce has an improper authorization vulnerability that allows low-privileged attackers to bypass security features and access minor information without user interaction. This affects Adobe Co...

CVE-2024-39405

MEDIUM CVSS 4.3 Aug 14, 2024

Adobe Commerce has an improper authorization vulnerability that allows low-privileged attackers to bypass security features and modify minor information without user interaction. This affects Adobe Co...

CVE-2024-39407

MEDIUM CVSS 4.3 Aug 14, 2024

CVE-2024-39407 is an improper authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures and modify minor information without user interaction. This...

CVE-2024-39409

MEDIUM CVSS 4.3 Aug 14, 2024

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Adobe Commerce that allows attackers to bypass security features and make minor integrity changes on behalf of authenticated use...

CVE-2024-34106

MEDIUM CVSS 5.3 Jun 13, 2024

This CVE describes an incorrect authorization vulnerability in Adobe Commerce that allows attackers to bypass security features and perform unauthorized actions with another user's privileges. It affe...