Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 190

All 190 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Adobe Commerce, a widely used enterprise e-commerce platform, focusing on security weaknesses and their associated risk classifications. It collects information on common vulnerability types such as cross-site scripting, remote code execution, and insecure direct object references, covering entries from 2015 to the present. This comprehensive dataset allows security professionals and administrators to track vendor advisories from Adobe, understand the evolution of specific weakness classes within this software ecosystem, and look up a product's historical vulnerability trends over time. By centralizing this information, the page serves as a reference for assessing security posture, prioritizing patch management, and conducting risk analysis. Users can explore how different vulnerability categories have impacted the platform, review the frequency of reported issues, and identify patterns that may indicate systemic weaknesses in the codebase or configuration. The data is organized to facilitate easy navigation through historical records, enabling stakeholders to make informed decisions about infrastructure security and compliance. This resource is intended for technical teams, security auditors, and business owners who require accurate, up-to-date insights into the security landscape of Adobe Commerce without sifting through fragmented sources. The aggregation process ensures that relevant details are available in a structured format, supporting proactive defense strategies and continuous monitoring efforts.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2025-54236 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 9.1 Critical2025-09-09
CVE-2025-49556 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2025-08-12
CVE-2025-49557 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-08-12
CVE-2025-49558 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 5.9 Medium2025-08-12
CVE-2025-49554 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 7.5 High2025-08-12
CVE-2025-49559 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 5.3 Medium2025-08-12
CVE-2025-49555 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 8.1 High2025-08-12
CVE-2025-49550 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-06-25
CVE-2025-49549 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 2.7 Low2025-06-25
CVE-2025-27206 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-06-10
CVE-2025-43586 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 8.1 High2025-06-10
CVE-2025-47110 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.4 High2025-06-10
CVE-2025-27207 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-06-10
CVE-2025-43585 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 8.2 High2025-06-10
CVE-2025-27190 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27191 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27192 Adobe Commerce | Insufficiently Protected Credentials (CWE-522) CWE-522 2.7 Low2025-04-08
CVE-2025-27188 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-04-08
CVE-2025-27189 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2025-04-08
CVE-2025-24422 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-02-11
CVE-2025-24414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24434 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 9.1 Critical2025-02-11
CVE-2025-24437 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.4 Medium2025-02-11
CVE-2025-24415 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24411 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 8.1 High2025-02-11
CVE-2025-24416 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24420 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-02-11
CVE-2025-24419 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-02-11
CVE-2025-24413 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24432 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 3.7 Low2025-02-11

All 190 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.