4.3

CVSS3.1

CVE-2026-21297 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and โ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:36 p.m.

4.7

CVSS3.1

CVE-2026-21359 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have limited iโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:36 p.m.

7.5

CVSS3.1

CVE-2026-21309 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthoriโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:36 p.m.

5.4

CVSS3.1

CVE-2026-21292 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker attacker to inject malicious scripts into vulnerable form fields. Exploitation ofโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:34 p.m.

5.3

CVSS3.1

CVE-2026-21310 - Adobe Commerce | Improper Input Validation (CWE-20)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interacโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:36 p.m.

4.3

CVSS3.1

CVE-2026-21285 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and โ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:30 p.m.

8.7

CVSS3.1

CVE-2026-21290 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript mayโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 12, 2026, 3:55 a.m.

7.5

CVSS3.1

CVE-2026-21289 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthoriโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:32 p.m.

8.1

CVSS3.1

CVE-2026-21361 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript mโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 12, 2026, 3:55 a.m.

6.8

CVSS3.1

CVE-2026-21360 - Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWโ€ฆ

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. A high-privileged attacker could leveโ€ฆ

๐Ÿ“… Published: March 11, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 11, 2026, 5:35 p.m.
Total resulsts: 337541
Page 32 of 33,755
ยซ previous page ยป next page
Filters