Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 190

All 190 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Adobe Commerce, a widely used enterprise e-commerce platform, focusing on security weaknesses and their associated risk classifications. It collects information on common vulnerability types such as cross-site scripting, remote code execution, and insecure direct object references, covering entries from 2015 to the present. This comprehensive dataset allows security professionals and administrators to track vendor advisories from Adobe, understand the evolution of specific weakness classes within this software ecosystem, and look up a product's historical vulnerability trends over time. By centralizing this information, the page serves as a reference for assessing security posture, prioritizing patch management, and conducting risk analysis. Users can explore how different vulnerability categories have impacted the platform, review the frequency of reported issues, and identify patterns that may indicate systemic weaknesses in the codebase or configuration. The data is organized to facilitate easy navigation through historical records, enabling stakeholders to make informed decisions about infrastructure security and compliance. This resource is intended for technical teams, security auditors, and business owners who require accurate, up-to-date insights into the security landscape of Adobe Commerce without sifting through fragmented sources. The aggregation process ensures that relevant details are available in a structured format, supporting proactive defense strategies and continuous monitoring efforts.

Vendor: Adobe

CVE ID Title CVSS Severity Published
CVE-2026-34648 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High 2026-05-12
CVE-2026-34649 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High 2026-05-12
CVE-2026-34655 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium 2026-05-12
CVE-2026-34651 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High 2026-05-12
CVE-2026-34654 Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) CWE-1395 5.3 Medium 2026-05-12
CVE-2026-34646 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High 2026-05-12
CVE-2026-21291 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium 2026-03-11
CVE-2026-21293 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 5.5 Medium 2026-03-11
CVE-2026-21282 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 5.3 Medium 2026-03-11
CVE-2026-21286 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.3 Medium 2026-03-11
CVE-2026-21294 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 5.5 Medium 2026-03-11
CVE-2026-21284 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High 2026-03-11
CVE-2026-21297 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium 2026-03-11
CVE-2026-21359 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.7 Medium 2026-03-11
CVE-2026-21309 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High 2026-03-11
CVE-2026-21292 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 5.4 Medium 2026-03-11
CVE-2026-21310 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 5.3 Medium 2026-03-11
CVE-2026-21285 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium 2026-03-11
CVE-2026-21290 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High 2026-03-11
CVE-2026-21361 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High 2026-03-11
CVE-2026-21289 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High 2026-03-11
CVE-2026-21360 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 6.8 Medium 2026-03-11
CVE-2026-21296 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium 2026-03-11
CVE-2026-21311 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.0 High 2026-03-11
CVE-2026-21295 Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) CWE-601 3.1 Low 2026-03-11
CVE-2025-54267 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium 2025-10-14
CVE-2025-54266 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium 2025-10-14
CVE-2025-54263 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 8.1 High 2025-10-14
CVE-2025-54264 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High 2025-10-14
CVE-2025-54265 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.9 Medium 2025-10-14

All 190 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.