Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
adobe commerce vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2022-35698
Adobe Commerce versions 2.4.4-p1 (and previous versions) and 2.4.5 (and previous versions) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
2 Github repositories
7.5
CVSSv3
CVE-2023-22247
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injecti...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
4.3
CVSSv3
CVE-2023-22251
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
5.3
CVSSv3
CVE-2023-22250
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a use...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
7.2
CVSSv3
CVE-2022-24093
Adobe Commerce versions 2.4.3-p1 (and previous versions) and 2.3.7-p2 (and previous versions) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code executio...
Adobe Magento Open Source 2.3.7
Adobe Magento Open Source 2.4.3
Adobe Magento Open Source
Adobe Commerce 2.3.7
Adobe Commerce 2.4.3
Adobe Commerce
4.8
CVSSv3
CVE-2023-22249
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged malicious user to inject malicious scripts into vulnerable form fields. Malici...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
9.8
CVSSv3
CVE-2022-24086
Adobe Commerce versions 2.4.3-p1 (and previous versions) and 2.3.7-p2 (and previous versions) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code ex...
Adobe Commerce
Adobe Commerce 2.3.7
Adobe Commerce 2.4.3
Magento Magento
Magento Magento 2.3.7
Magento Magento 2.4.3
11 Github repositories
4 Articles
7.5
CVSSv3
CVE-2021-36030
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
8.8
CVSSv3
CVE-2021-36032
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/m...
Adobe Magento Open Source
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source 2.4.2
6.5
CVSSv3
CVE-2021-36038
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an improper input validation vulnerability in the Multishipping Module. An authenticated attacker could leverage this vulnerability to achie...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »