Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
adobe commerce vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-22249
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged malicious user to inject malicious scripts into vulnerable form fields. Malici...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
NA
CVE-2023-22250
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a use...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
NA
CVE-2022-24093
Adobe Commerce versions 2.4.3-p1 (and previous versions) and 2.3.7-p2 (and previous versions) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code executio...
Adobe Magento Open Source 2.3.7
Adobe Magento Open Source 2.4.3
Adobe Magento Open Source
Adobe Commerce 2.3.7
Adobe Commerce 2.4.3
Adobe Commerce
NA
CVE-2023-22251
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
NA
CVE-2022-35689
Adobe Commerce versions 2.4.4-p1 (and previous versions) and 2.4.5 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user...
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
1 Github repository
NA
CVE-2022-35698
Adobe Commerce versions 2.4.4-p1 (and previous versions) and 2.4.5 (and previous versions) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
Adobe Commerce 2.4.4
Adobe Magento Open Source
Adobe Magento Open Source 2.4.5
Adobe Magento Open Source 2.4.4
Adobe Commerce 2.4.5
Adobe Commerce
2 Github repositories
10
CVSSv2
CVE-2022-24086
Adobe Commerce versions 2.4.3-p1 (and previous versions) and 2.3.7-p2 (and previous versions) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code ex...
Adobe Commerce
Adobe Commerce 2.3.7
Adobe Commerce 2.4.3
Magento Magento
Magento Magento 2.3.7
Magento Magento 2.4.3
11 Github repositories
4 Articles
4
CVSSv2
CVE-2021-36012
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of a...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
6.5
CVSSv2
CVE-2021-36022
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to ach...
Adobe Magento Open Source
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source 2.4.2
4.3
CVSSv2
CVE-2021-36026
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an malicious user to inject malic...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
remote code execution
CVE-2024-34909
CVE-2024-3317
SSTI
CVE-2024-3400
CVE-2024-30051
wireless
CVE-2024-4622
CVE-2024-4908
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »