Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 169

All 169 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for Adobe Commerce, a popular e-commerce platform developed by Adobe Inc., categorized under various weakness types and security tags. The collection focuses on critical and high-severity issues affecting the product’s core functionality, extensions, and integrated components. It encompasses vulnerability data spanning from the early 2010s through the present, ensuring a comprehensive historical perspective alongside recent findings. The dataset includes issues related to remote code execution, cross-site scripting, SQL injection, and privilege escalation, reflecting the evolving threat landscape surrounding modern e-commerce architectures. Readers can track a vendor's advisories by following the chronological release notes and security bulletins published by Adobe. This structured approach allows users to understand a weakness class by analyzing patterns across different versions and modules of the software. Furthermore, individuals can look up a product's vulnerability history to assess long-term security trends and identify recurring problem areas. By centralizing this information, the page serves as a reference point for security professionals, developers, and system administrators who need to evaluate risk exposure. The content is organized to facilitate quick retrieval of relevant details without requiring extensive navigation. Users are encouraged to cross-reference this data with official patch notes and implementation guides to ensure accurate remediation. The goal is to provide a transparent and accessible resource for understanding the security posture of Adobe Commerce over time, supporting informed decision-making regarding updates and configuration hardening.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2026-21360 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 6.8 Medium2026-03-11
CVE-2026-21296 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2026-03-11
CVE-2026-21311 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.0 High2026-03-11
CVE-2026-21295 Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) CWE-601 3.1 Low2026-03-11
CVE-2025-54267 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium2025-10-14
CVE-2025-54266 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2025-10-14
CVE-2025-54263 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 8.1 High2025-10-14
CVE-2025-54265 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.9 Medium2025-10-14
CVE-2025-54264 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2025-10-14
CVE-2025-54236 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 9.1 Critical2025-09-09
CVE-2025-49556 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2025-08-12
CVE-2025-49557 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-08-12
CVE-2025-49558 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 5.9 Medium2025-08-12
CVE-2025-49554 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 7.5 High2025-08-12
CVE-2025-49559 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 5.3 Medium2025-08-12
CVE-2025-49555 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 8.1 High2025-08-12
CVE-2025-49550 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-06-25
CVE-2025-49549 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 2.7 Low2025-06-25
CVE-2025-27206 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-06-10
CVE-2025-43586 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 8.1 High2025-06-10
CVE-2025-47110 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.4 High2025-06-10
CVE-2025-27207 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-06-10
CVE-2025-43585 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 8.2 High2025-06-10
CVE-2025-27190 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27192 Adobe Commerce | Insufficiently Protected Credentials (CWE-522) CWE-522 2.7 Low2025-04-08
CVE-2025-27191 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27188 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-04-08
CVE-2025-27189 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2025-04-08
CVE-2025-24422 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-02-11
CVE-2025-24414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11

All 169 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.