Adobe illustrator是美国Adobe公司的一款矢量图形设计和插图软件。 Adobe Illustrator Desktop 2026 30.5及之前版本和Illustrator Desktop 2025 29.8.7及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Untrusted Search Path问题,可能导致当前用户环境中执行任意代码。利用该漏洞需要用户交互,即受害者必须打开恶意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Adobe | Illustrator Desktop 2025 | ≤ 29.8.7 |
affected |
29.8.9 |
unaffected | ||
| Adobe | Illustrator Desktop 2026 | ≤ 30.5 |
affected |
30.6 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Illustrator Desktop 2026 | 0 ~ 30.5 | - |
|
| Adobe | Illustrator Desktop 2025 | 0 ~ 29.8.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48318 | 9.9 CRITICAL | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' |
| CVE-2026-48322 | 9.9 CRITICAL | ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) |
| CVE-2026-48284 | 9.6 CRITICAL | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-48359 | 9.6 CRITICAL | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') ( |
| CVE-2026-48259 | 9.6 CRITICAL | Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-48325 | 9.3 CRITICAL | ColdFusion | Missing Authentication for Critical Function (CWE-306) |
| CVE-2026-48356 | 9.3 CRITICAL | Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) |
| CVE-2026-48321 | 9.3 CRITICAL | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-48334 | 9.3 CRITICAL | Illustrator | Improper Input Validation (CWE-20) |
| CVE-2026-48324 | 9.1 CRITICAL | ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje |
| CVE-2026-48319 | 9.1 CRITICAL | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' |
| CVE-2026-48358 | 9.1 CRITICAL | Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) |
| CVE-2026-48327 | 9.0 CRITICAL | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-47994 | 8.7 HIGH | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48310 | 8.6 HIGH | Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('P |
| CVE-2026-48350 | 8.6 HIGH | Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') ( |
| CVE-2026-48252 | 8.6 HIGH | Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306) |
| CVE-2026-47988 | 8.6 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-48320 | 8.5 HIGH | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2026-48290 | 8.2 HIGH | CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) |
Showing top 20 of 88 CVEs. View all on vendor page → →
No comments yet