5.3

CVSS3.1

CVE-2026-21310 - Adobe Commerce | Improper Input Validation (CWE-20)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interac…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

4.3

CVSS3.1

CVE-2026-21285 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and …

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

8.7

CVSS3.1

CVE-2026-21290 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

7.5

CVSS3.1

CVE-2026-21289 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthori…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

8.1

CVSS3.1

CVE-2026-21361 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript m…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

6.8

CVSS3.1

CVE-2026-21360 - Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CW…

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. A high-privileged attacker could leve…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

4.3

CVSS3.1

CVE-2026-21296 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and …

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

8

CVSS3.1

CVE-2026-21311 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript ma…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

3.1

CVSS3.1

CVE-2026-21295 - Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issu…

πŸ“… Published: March 11, 2026, 2:19 a.m. πŸ”„ Last Modified: March 20, 2026, 2:38 p.m.

6.1

CVSS3.1

CVE-2025-12473 - RTMKit <= 1.6.8 - Reflected Cross-Site Scripting via 'themebuilder' Parameter

The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip…

πŸ“… Published: March 11, 2026, 1:22 a.m. πŸ”„ Last Modified: April 22, 2026, 9:27 p.m.
Total resulsts: 349182
Page 1190 of 34,919
Β« previous page Β» next page
Filters