Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 190

All 190 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Adobe Commerce, a widely used enterprise e-commerce platform, focusing on security weaknesses and their associated risk classifications. It collects information on common vulnerability types such as cross-site scripting, remote code execution, and insecure direct object references, covering entries from 2015 to the present. This comprehensive dataset allows security professionals and administrators to track vendor advisories from Adobe, understand the evolution of specific weakness classes within this software ecosystem, and look up a product's historical vulnerability trends over time. By centralizing this information, the page serves as a reference for assessing security posture, prioritizing patch management, and conducting risk analysis. Users can explore how different vulnerability categories have impacted the platform, review the frequency of reported issues, and identify patterns that may indicate systemic weaknesses in the codebase or configuration. The data is organized to facilitate easy navigation through historical records, enabling stakeholders to make informed decisions about infrastructure security and compliance. This resource is intended for technical teams, security auditors, and business owners who require accurate, up-to-date insights into the security landscape of Adobe Commerce without sifting through fragmented sources. The aggregation process ensures that relevant details are available in a structured format, supporting proactive defense strategies and continuous monitoring efforts.

Vendor: Adobe

CVE ID Title CVSS Severity Published
CVE-2026-48414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 7.7 High 2026-08-11
CVE-2026-48416 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High 2026-08-11
CVE-2026-48415 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.6 High 2026-08-11
CVE-2026-48413 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High 2026-08-11
CVE-2026-48412 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 2.7 Low 2026-08-11
CVE-2026-48411 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium 2026-08-11
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 9.1 Critical 2026-08-11
CVE-2026-47984 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 8.2 High 2026-07-14
CVE-2026-47997 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.9 Medium 2026-07-14
CVE-2026-47988 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 8.6 High 2026-07-14
CVE-2026-48358 Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) CWE-116 9.1 Critical 2026-07-14
CVE-2026-47999 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium 2026-07-14
CVE-2026-48356 Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) CWE-434 9.3 Critical 2026-07-14
CVE-2026-47998 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.9 Medium 2026-07-14
CVE-2026-48000 Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) CWE-601 6.1 Medium 2026-07-14
CVE-2026-47995 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High 2026-07-14
CVE-2026-48001 Adobe Commerce | Information Exposure (CWE-200) CWE-200 3.7 Low 2026-07-14
CVE-2026-47996 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.8 Medium 2026-07-14
CVE-2026-48371 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 5.4 Medium 2026-07-14
CVE-2026-47994 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High 2026-07-14
CVE-2026-47992 Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) CWE-89 7.2 High 2026-07-14
CVE-2026-34656 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 4.3 Medium 2026-05-12
CVE-2026-34658 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium 2026-05-12
CVE-2026-34650 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High 2026-05-12
CVE-2026-34686 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High 2026-05-12
CVE-2026-34647 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 7.4 High 2026-05-12
CVE-2026-34685 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 3.4 Low 2026-05-12
CVE-2026-34653 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 8.7 High 2026-05-12
CVE-2026-34652 Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) CWE-1395 7.5 High 2026-05-12
CVE-2026-34645 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High 2026-05-12

All 190 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.