5.4

CVSS3.1

CVE-2025-24437 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view or modify select information. Exploit…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 2:21 p.m.

9.1

CVSS3.1

CVE-2025-24434 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Explo…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8.7

CVSS3.1

CVE-2025-24415 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8.1

CVSS3.1

CVE-2025-24411 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unautho…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8.7

CVSS3.1

CVE-2025-24416 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-24420 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this i…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:16 p.m.

8.7

CVSS3.1

CVE-2025-24413 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-24419 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this i…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:17 p.m.

3.7

CVSS3.1

CVE-2025-24432 - Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 2:25 p.m.

6.5

CVSS3.1

CVE-2025-24424 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unautho…

📅 Published: Feb. 11, 2025, 5:37 p.m. 🔄 Last Modified: April 16, 2025, 5:16 p.m.
Total resulsts: 343968
Page 6265 of 34,397
« previous page » next page
Filters