8.7

CVSS3.1

CVE-2025-24413 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-24419 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this i…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:17 p.m.

3.7

CVSS3.1

CVE-2025-24432 - Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 2:25 p.m.

6.5

CVSS3.1

CVE-2025-24424 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unautho…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:16 p.m.

3.7

CVSS3.1

CVE-2025-24430 - Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 2:25 p.m.

3.5

CVSS3.1

CVE-2025-24429 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this vulnerability to bypass security…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 2:27 p.m.

4.3

CVSS3.1

CVE-2025-24436 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view select information. Exploitation of t…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 2:53 p.m.

7.1

CVSS3.1

CVE-2025-24407 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low privileged attacker could exploit this vulnerability to perform actions with permissions that were…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:18 p.m.

8.7

CVSS3.1

CVE-2025-24438 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-24423 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to modify select data. Exploitation of this issue…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:16 p.m.
Total resulsts: 343942
Page 6263 of 34,395
« previous page » next page
Filters