📦 Configured Commerce

by Optimizely

🔍 What is Configured Commerce?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22386

HIGH CVSS 7.3 Jan 4, 2025

This vulnerability allows session tokens from logged-out users to remain active and usable in Optimizely Configured Commerce B2B storefronts. Attackers could potentially hijack sessions and perform un...

CVE-2025-22387

HIGH CVSS 7.5 Jan 4, 2025

This vulnerability in Optimizely Configured Commerce exposes session tokens in URL parameters, allowing attackers to hijack authenticated user sessions. It affects all Optimizely Configured Commerce i...

CVE-2025-22384

HIGH CVSS 7.5 Jan 4, 2025

This vulnerability allows attackers to purchase discontinued products by manipulating requests before they reach the server. It affects Optimizely Configured Commerce B2B storefronts running versions ...

CVE-2024-56174

HIGH CVSS 8.1 Dec 18, 2024

This vulnerability allows attackers to inject malicious scripts into Optimizely Configured Commerce search history, which then execute in users' browsers when they view their search history. It affect...

CVE-2025-22385

MEDIUM CVSS 5.9 Jan 4, 2025

Optimizely Configured Commerce versions before 5.2.2408 allow mass account creation without email confirmation for new accounts. This affects all B2B e-commerce deployments using vulnerable versions, ...

CVE-2025-22383

MEDIUM CVSS 4.6 Jan 4, 2025

A cross-site scripting (XSS) vulnerability exists in Optimizely Configured Commerce's Contact Us functionality that allows visitors to inject unfiltered HTML markup into email messages. This affects a...

CVE-2024-56173

MEDIUM CVSS 4.7 Dec 18, 2024

This is a stored cross-site scripting (XSS) vulnerability in Optimizely Configured Commerce where malicious JavaScript in SVG documents can be injected and later executed in users' browsers. It affect...