7.5

CVSS3.1

CVE-2025-24406 - Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CW…

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An unauthenticated attacker could exploit this vuln…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 17, 2025, 4:09 p.m.

8.7

CVSS3.1

CVE-2025-24417 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8.2

CVSS3.1

CVE-2025-24409 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access,…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:18 p.m.

5.3

CVSS3.1

CVE-2025-24425 - Adobe Commerce | Business Logic Errors (CWE-840)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to circumvent intended security mechanisms by manipulating the …

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

4.3

CVSS3.1

CVE-2025-24421 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to read select data. Exploitation of this iss…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 17, 2025, 3:44 p.m.

8.7

CVSS3.1

CVE-2025-24412 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2025-24427 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unautho…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 17, 2025, 3:44 p.m.

6.5

CVSS3.1

CVE-2025-24426 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unautho…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:16 p.m.

5.4

CVSS3.1

CVE-2025-24428 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: March 3, 2025, 3:31 p.m.

8.7

CVSS3.1

CVE-2025-24410 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 349182
Page 6788 of 34,919
« previous page » next page
Filters