4.8

CVSS3.1

CVE-2026-21291 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this is…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

5.5

CVSS3.1

CVE-2026-21293 - Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-s…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

5.3

CVSS3.1

CVE-2026-21282 - Adobe Commerce | Improper Input Validation (CWE-20)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causi…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

5.3

CVSS3.1

CVE-2026-21286 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited u…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

5.5

CVSS3.1

CVE-2026-21294 - Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-s…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

8.1

CVSS3.1

CVE-2026-21284 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript ma…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

4.3

CVSS3.1

CVE-2026-21297 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and …

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

4.7

CVSS3.1

CVE-2026-21359 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have limited i…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

7.5

CVSS3.1

CVE-2026-21309 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthori…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

5.4

CVSS3.1

CVE-2026-21292 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker attacker to inject malicious scripts into vulnerable form fields. Exploitation of…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.
Total resulsts: 349182
Page 1189 of 34,919
Β« previous page Β» next page
Filters