Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 169

All 169 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of common weakness vulnerabilities associated with Adobe Commerce, a leading e-commerce platform. It collects security issues affecting the software’s core functionalities, extensions, and integrations, covering incidents reported from January 2018 to the present. By consolidating this data, the page allows users to track vendor advisories as they are released, ensuring that administrators can stay informed about emerging threats and required patches. Visitors can also dive deeper into specific weakness classes, such as cross-site scripting or SQL injection, to understand the underlying mechanics and potential impact on their deployment environments. Additionally, the resource enables users to look up a product's vulnerability history, providing a longitudinal view of security trends and the effectiveness of historical remediation efforts. This structured approach helps security professionals evaluate the risk profile of Adobe Commerce installations over time, facilitating more informed decision-making regarding upgrade paths and mitigation strategies. The aggregation process ensures that fragmented data from multiple sources is unified into a single, accessible reference point, reducing the manual effort required to monitor security updates. By focusing on factual reporting and historical context, this page serves as a practical tool for maintaining the integrity and stability of Adobe Commerce deployments without bias or promotional content.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2024-45127 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2024-10-10
CVE-2024-45128 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.4 Medium2024-10-10
CVE-2024-45133 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-45124 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2024-10-10
CVE-2024-45123 Adobe Commerce | Cross-site Scripting (Reflected XSS) (CWE-79) CWE-79 6.1 Medium2024-10-10
CVE-2024-45121 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45117 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 7.6 High2024-10-10
CVE-2024-45115 Adobe Commerce | Improper Authentication (CWE-287) CWE-287 9.8 Critical2024-10-10
CVE-2024-45116 Adobe Commerce | Cross-site Scripting (XSS) (CWE-79) CWE-79 8.1 High2024-10-10
CVE-2024-45119 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 4.9 Medium2024-10-10
CVE-2024-45122 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45120 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 3.1 Low2024-10-10
CVE-2024-45135 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-45130 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45132 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium2024-10-10
CVE-2024-45148 Adobe Commerce | Improper Authentication (CWE-287) CWE-287 8.8 High2024-10-10
CVE-2024-45131 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.4 Medium2024-10-10
CVE-2024-45134 Adobe Commerce | Information Exposure (CWE-200) CWE-200 2.7 Low2024-10-10
CVE-2024-45129 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45118 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2024-10-10
CVE-2024-45125 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2024-10-10
CVE-2024-45149 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-39419 A user without ship permissions can ship the orders CWE-285 4.3 Medium2024-08-14
CVE-2024-39403 Stored XSS through Webhook module public key configuration CWE-79 7.6 High2024-08-14
CVE-2024-39418 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 5.4 Medium2024-08-14
CVE-2024-39413 An unauthorized user can export the Invoiced Sales Report CWE-285 4.3 Medium2024-08-14
CVE-2024-39408 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2024-08-14
CVE-2024-39399 [Paris] Path Traversal lead to local file read CWE-22 7.7 High2024-08-14
CVE-2024-39417 An unauthorized user can export the Shipping Report CWE-285 4.3 Medium2024-08-14
CVE-2024-39410 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2024-08-14

All 169 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.