Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
adobe adobe commerce vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2021-39864
Adobe Commerce versions 2.4.2-p2 (and previous versions), 2.4.3 (and previous versions) and 2.3.7p1 (and previous versions) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to ...
Adobe Commerce 2.3.7
Adobe Commerce
Adobe Commerce 2.4.2
Adobe Commerce 2.4.3
Adobe Magento Open Source 2.3.7
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
Adobe Magento Open Source 2.4.3
5.4
CVSSv3
CVE-2022-35698
Adobe Commerce versions 2.4.4-p1 (and previous versions) and 2.4.5 (and previous versions) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
2 Github repositories
7.2
CVSSv3
CVE-2022-24093
Adobe Commerce versions 2.4.3-p1 (and previous versions) and 2.3.7-p2 (and previous versions) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code executio...
Adobe Magento Open Source 2.3.7
Adobe Magento Open Source 2.4.3
Adobe Magento Open Source
Adobe Commerce 2.3.7
Adobe Commerce 2.4.3
Adobe Commerce
7.5
CVSSv3
CVE-2023-22247
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injecti...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
4.8
CVSSv3
CVE-2023-22249
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged malicious user to inject malicious scripts into vulnerable form fields. Malici...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
5.3
CVSSv3
CVE-2023-22250
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a use...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
4.3
CVSSv3
CVE-2023-22251
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
5.3
CVSSv3
CVE-2022-35689
Adobe Commerce versions 2.4.4-p1 (and previous versions) and 2.4.5 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
1 Github repository
6.5
CVSSv3
CVE-2021-36012
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of a...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
7.2
CVSSv3
CVE-2021-36031
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by a Path Traversal vulnerability via the `theme[preview_image]` parameter. An attacker with admin privileges could leverage this vulnerability...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »