Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
adobe magento open source vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2021-21012
Magento versions 2.4.1 (and previous versions), 2.4.0-p1 (and previous versions) and 2.3.6 (and previous versions) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.
Adobe Magento Commerce
Adobe Magento Commerce 2.4.0
Adobe Magento Commerce 2.4.1
Adobe Magento Open Source
Adobe Magento Open Source 2.4.0
Adobe Magento Open Source 2.4.1
6.5
CVSSv3
CVE-2021-39864
Adobe Commerce versions 2.4.2-p2 (and previous versions), 2.4.3 (and previous versions) and 2.3.7p1 (and previous versions) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to ...
Adobe Commerce
Adobe Commerce 2.3.7
Adobe Commerce 2.4.2
Adobe Commerce 2.4.3
Adobe Magento Open Source
Adobe Magento Open Source 2.3.7
Adobe Magento Open Source 2.4.2
Adobe Magento Open Source 2.4.3
5.3
CVSSv3
CVE-2022-35689
Adobe Commerce versions 2.4.4-p1 (and previous versions) and 2.4.5 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user...
Adobe Commerce
Adobe Commerce 2.4.4
Adobe Commerce 2.4.5
Adobe Magento Open Source
Adobe Magento Open Source 2.4.4
Adobe Magento Open Source 2.4.5
1 Github repository
5.4
CVSSv3
CVE-2022-35698
Adobe Commerce versions 2.4.4-p1 (and previous versions) and 2.4.5 (and previous versions) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
Adobe Commerce
Adobe Commerce 2.4.4
Adobe Commerce 2.4.5
Adobe Magento Open Source
Adobe Magento Open Source 2.4.4
Adobe Magento Open Source 2.4.5
2 Github repositories
7.5
CVSSv3
CVE-2023-22247
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injecti...
Adobe Commerce
Adobe Commerce 2.4.4
Adobe Commerce 2.4.5
Adobe Magento Open Source
Adobe Magento Open Source 2.4.4
Adobe Magento Open Source 2.4.5
4.3
CVSSv3
CVE-2023-22251
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
Adobe Commerce
Adobe Commerce 2.4.4
Adobe Commerce 2.4.5
Adobe Magento Open Source
Adobe Magento Open Source 2.4.4
Adobe Magento Open Source 2.4.5
4.8
CVSSv3
CVE-2023-22249
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged malicious user to inject malicious scripts into vulnerable form fields. Malici...
Adobe Commerce
Adobe Commerce 2.4.4
Adobe Commerce 2.4.5
Adobe Magento Open Source
Adobe Magento Open Source 2.4.4
Adobe Magento Open Source 2.4.5
5.3
CVSSv3
CVE-2023-22250
Adobe Commerce versions 2.4.4-p2 (and previous versions) and 2.4.5-p1 (and previous versions) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a use...
Adobe Commerce
Adobe Commerce 2.4.4
Adobe Commerce 2.4.5
Adobe Magento Open Source
Adobe Magento Open Source 2.4.4
Adobe Magento Open Source 2.4.5
7.2
CVSSv3
CVE-2022-24093
Adobe Commerce versions 2.4.3-p1 (and previous versions) and 2.3.7-p2 (and previous versions) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code executio...
Adobe Magento Open Source
Adobe Magento Open Source 2.3.7
Adobe Magento Open Source 2.4.3
Adobe Commerce
Adobe Commerce 2.3.7
Adobe Commerce 2.4.3
6.5
CVSSv3
CVE-2021-36012
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of a...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
booking & appointment - repute infosystems
CVE-2024-12826
stored XSS
7-zip
CVE-2025-0703
CVE-2025-0411
CVE-2024-43468
themerex addons
wireless
CVE-2025-23006
herd effects
CVE-2025-0707
information disclosure
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »