Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 190

All 190 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Adobe Commerce, a widely used enterprise e-commerce platform, focusing on security weaknesses and their associated risk classifications. It collects information on common vulnerability types such as cross-site scripting, remote code execution, and insecure direct object references, covering entries from 2015 to the present. This comprehensive dataset allows security professionals and administrators to track vendor advisories from Adobe, understand the evolution of specific weakness classes within this software ecosystem, and look up a product's historical vulnerability trends over time. By centralizing this information, the page serves as a reference for assessing security posture, prioritizing patch management, and conducting risk analysis. Users can explore how different vulnerability categories have impacted the platform, review the frequency of reported issues, and identify patterns that may indicate systemic weaknesses in the codebase or configuration. The data is organized to facilitate easy navigation through historical records, enabling stakeholders to make informed decisions about infrastructure security and compliance. This resource is intended for technical teams, security auditors, and business owners who require accurate, up-to-date insights into the security landscape of Adobe Commerce without sifting through fragmented sources. The aggregation process ensures that relevant details are available in a structured format, supporting proactive defense strategies and continuous monitoring efforts.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2024-39406 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 6.8 Medium2024-08-14
CVE-2024-39402 Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CWE-78 8.4 High2024-08-14
CVE-2024-39400 DOM XSS through integrations can impact other admins CWE-79 8.1 High2024-08-14
CVE-2024-39404 A user without Shop Policy Parameters section privilege can alter the shop policy parameters section CWE-285 4.3 Medium2024-08-14
CVE-2024-39405 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 4.3 Medium2024-08-14
CVE-2024-39415 An unauthorized user can export the Tax Sales Report CWE-285 4.3 Medium2024-08-14
CVE-2024-34106 Insecure Direct Object Reference - An attacker can able to erase the victim quote details CWE-863 5.3 Medium2024-06-13
CVE-2024-34109 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 7.2 High2024-06-13
CVE-2024-34103 Customer account takeover via web API call & subsequent password reset CWE-287 8.1 High2024-06-13
CVE-2024-34110 RCE in the Adobe Commerce Webhook module through a legit webhook definition CWE-434 7.2 High2024-06-13
CVE-2024-34111 SSRF in service connector CWE-918 6.5 Medium2024-06-13
CVE-2024-34105 Stored Cross Site Scripting in Order Comment CWE-79 4.8 Medium2024-06-13
CVE-2024-34107 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2024-06-13
CVE-2024-34104 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 8.2 High2024-06-13
CVE-2024-34102 XXE can expose crypt key and other secrets granting full admin access CWE-611 9.8 Critical2024-06-13
CVE-2024-34108 Large attack surface through legit webhook usage in Adobe Commerce CWE-20 9.1 Critical2024-06-13
CVE-2024-20758 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 9.0 Critical2024-04-10
CVE-2024-20759 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2024-04-10
CVE-2024-20716 Force high-usage of resources by generating unlimited coupons: Adobe Commerce CWE-400 4.9 Medium2024-02-15
CVE-2024-20717 Stored admin XSS via PayPal authentication certificate CWE-79 5.4 Medium2024-02-15
CVE-2024-20718 [Spain] CSRF to delete Requisition Lists at Adobe Commerce CWE-352 4.3 Medium2024-02-15
CVE-2024-20719 [Adobe Commerce] Stored XSS from low privileged admin user on every admin page, bypassing CVE-2023-29297 CWE-79 9.1 Critical2024-02-15
CVE-2024-20720 Command injection in data collector backup due to insufficient patching of CVE-2023-38208 CWE-78 9.1 Critical2024-02-15
CVE-2023-38251 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 5.3 Medium2023-10-13
CVE-2023-38219 Validate Your Inputs | Cross-site Scripting (Stored XSS) (CWE-79) - Customer to Admin stored XSS with Gift wrapping CWE-79 8.7 High2023-10-13
CVE-2023-38220 Full page cache enumeration via cookie X-Magento-Vary CWE-285 7.5 High2023-10-13
CVE-2023-26367 Error based file extraction via PHP filter chains during product bulk import logic CWE-20 4.9 Medium2023-10-13
CVE-2023-26366 Validate Your Inputs | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 6.8 Medium2023-10-13
CVE-2023-38218 Incorrect Authorization - Customer account takeover CWE-863 8.8 High2023-10-13
CVE-2023-38250 Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) CWE-89 8.0 High2023-10-13

All 190 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.