CVE-2026-47995: Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47995?
CVE-2026-47995 has a high severity rating of 8.1.
How do I fix CVE-2026-47995?
To fix CVE-2026-47995, update your Adobe Commerce installation to the latest patched version.
What type of vulnerability is CVE-2026-47995?
CVE-2026-47995 is a stored Cross-Site Scripting (XSS) vulnerability.
Who can exploit CVE-2026-47995?
A high-privileged attacker can exploit CVE-2026-47995 to inject malicious scripts into vulnerable form fields.
What impact does CVE-2026-47995 have on users?
If exploited, CVE-2026-47995 may allow malicious JavaScript to be executed in a victim's browser.