Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 190

All 190 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Adobe Commerce, a widely used enterprise e-commerce platform, focusing on security weaknesses and their associated risk classifications. It collects information on common vulnerability types such as cross-site scripting, remote code execution, and insecure direct object references, covering entries from 2015 to the present. This comprehensive dataset allows security professionals and administrators to track vendor advisories from Adobe, understand the evolution of specific weakness classes within this software ecosystem, and look up a product's historical vulnerability trends over time. By centralizing this information, the page serves as a reference for assessing security posture, prioritizing patch management, and conducting risk analysis. Users can explore how different vulnerability categories have impacted the platform, review the frequency of reported issues, and identify patterns that may indicate systemic weaknesses in the codebase or configuration. The data is organized to facilitate easy navigation through historical records, enabling stakeholders to make informed decisions about infrastructure security and compliance. This resource is intended for technical teams, security auditors, and business owners who require accurate, up-to-date insights into the security landscape of Adobe Commerce without sifting through fragmented sources. The aggregation process ensures that relevant details are available in a structured format, supporting proactive defense strategies and continuous monitoring efforts.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2024-45119 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 4.9 Medium2024-10-10
CVE-2024-45122 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45120 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 3.1 Low2024-10-10
CVE-2024-45135 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-45130 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45132 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium2024-10-10
CVE-2024-45148 Adobe Commerce | Improper Authentication (CWE-287) CWE-287 8.8 High2024-10-10
CVE-2024-45131 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.4 Medium2024-10-10
CVE-2024-45134 Adobe Commerce | Information Exposure (CWE-200) CWE-200 2.7 Low2024-10-10
CVE-2024-45129 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45118 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2024-10-10
CVE-2024-45125 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2024-10-10
CVE-2024-45149 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-39419 A user without ship permissions can ship the orders CWE-285 4.3 Medium2024-08-14
CVE-2024-39403 Stored XSS through Webhook module public key configuration CWE-79 7.6 High2024-08-14
CVE-2024-39418 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 5.4 Medium2024-08-14
CVE-2024-39413 An unauthorized user can export the Invoiced Sales Report CWE-285 4.3 Medium2024-08-14
CVE-2024-39408 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2024-08-14
CVE-2024-39399 [Paris] Path Traversal lead to local file read CWE-22 7.7 High2024-08-14
CVE-2024-39417 An unauthorized user can export the Shipping Report CWE-285 4.3 Medium2024-08-14
CVE-2024-39410 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2024-08-14
CVE-2024-39398 OTP 2FA can be bruteforced CWE-307 7.4 High2024-08-14
CVE-2024-39407 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 4.3 Medium2024-08-14
CVE-2024-39401 Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CWE-78 8.4 High2024-08-14
CVE-2024-39397 Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) CWE-434 9.0 Critical2024-08-14
CVE-2024-39411 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 4.3 Medium2024-08-14
CVE-2024-39409 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2024-08-14
CVE-2024-39416 Unauthorized user can export Orders Sale Report CWE-285 4.3 Medium2024-08-14
CVE-2024-39414 Being able to import/export tax rates without proper privileges CWE-284 4.3 Medium2024-08-14
CVE-2024-39412 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 4.3 Medium2024-08-14

All 190 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.