Latest adobe commerce Vulnerabilities

Force high-usage of resources by generating unlimited coupons: Adobe Commerce
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
Adobe Commerce=2.4.4-p5
and 11 more
Stored admin XSS via PayPal authentication certificate
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
Adobe Commerce=2.4.4-p5
and 11 more
[Spain] CSRF to delete Requisition Lists at Adobe Commerce
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
Adobe Commerce=2.4.4-p5
and 11 more
[Adobe Commerce] Stored XSS from low privileged admin user on every admin page, bypassing CVE-2023-29297
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
Adobe Commerce=2.4.4-p5
and 11 more
Command injection in data collector backup due to insufficient patching of CVE-2023-38208
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
Adobe Commerce=2.4.4-p5
and 11 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an S...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that coul...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an S...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an S...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Authorization vulnerability that could lead in ...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an improper input validation vulnerability. An authenticate...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that coul...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Input Validation vulnerability that could lead ...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that cou...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 52 more
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and c...
Adobe Magento Open Source<2.3.7
Adobe Magento Open Source>=2.4.0<2.4.3
Adobe Magento Open Source=2.3.7-p1
Adobe Magento Open Source=2.3.7-p2
Adobe Magento Open Source=2.4.3
Adobe Magento Open Source=2.4.3-p1
and 6 more
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arb...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
and 6 more
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerability that could lead to a Security feature bypass....
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
and 6 more
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inje...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.4-p3
Adobe Commerce=2.4.4-p4
and 6 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that could result in a security feature bypass. A l...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Improper Neutralization of Special Elements Used in a Template Engine vulnerability tha...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. ...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. ...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file syst...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an XML Injection vulnerability. An attacker with low privileges can trigger a specially c...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file syst...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. ...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability that could lead to a security feature bypass. An at...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. ...
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
Adobe Commerce=2.3.7-p4
Adobe Commerce=2.3.7-p4-ext1
and 29 more
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could lev...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.5
Adobe Commerce=2.4.5-p1
and 6 more
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerab...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.5
Adobe Commerce=2.4.5-p1
and 6 more
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.5
Adobe Commerce=2.4.5-p1
and 6 more
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can ...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.4-p2
Adobe Commerce=2.4.5
Adobe Commerce=2.4.5-p1
and 6 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an inse...
Adobe Commerce<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.3.7-p2
Adobe Commerce=2.3.7-p3
and 37 more
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and cou...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.5
Adobe Magento Open Source<2.4.4
Adobe Magento Open Source=2.4.4
and 2 more
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could levera...
Adobe Commerce<2.4.4
Adobe Commerce=2.4.4
Adobe Commerce=2.4.4-p1
Adobe Commerce=2.4.5
Adobe Magento Open Source<2.4.4
Adobe Magento Open Source=2.4.4
and 2 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. ...
Adobe Commerce>=2.4.0<2.4.4
Adobe Magento Commerce=2.3.7
Adobe Magento Commerce=2.3.7-p1
Adobe Magento Commerce=2.3.7-p2
Adobe Magento Commerce=2.3.7-p3
Adobe Magento Commerce=2.4.3
and 3 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An at...
composer/magento/community-edition>=2.4.0<2.4.3-p3
composer/magento/community-edition>=2.4.4<2.4.5
composer/magento/community-edition>=2.3.0<2.3.7-p4
Adobe Commerce>=2.3.0<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
and 17 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. ...
composer/magento/community-edition>=2.4.0<2.4.3-p3
composer/magento/community-edition>=2.4.4<2.4.5
composer/magento/community-edition>=2.3.0<2.3.7-p4
Adobe Commerce>=2.3.0<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
and 17 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker wit...
composer/magento/community-edition>=2.4.0<2.4.3-p3
composer/magento/community-edition>=2.4.4<2.4.5
composer/magento/community-edition>=2.3.0<2.3.7-p4
Adobe Commerce>=2.3.0<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
and 17 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to ...
composer/magento/community-edition>=2.4.0<2.4.3-p3
composer/magento/community-edition>=2.4.4<2.4.5
composer/magento/community-edition>=2.3.0<2.3.7-p4
Adobe Commerce>=2.3.0<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
and 17 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An att...
composer/magento/community-edition>=2.4.0<2.4.3-p3
composer/magento/community-edition>=2.4.4<2.4.5
composer/magento/community-edition>=2.3.0<2.3.7-p4
Adobe Commerce>=2.3.0<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
and 17 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnera...
composer/magento/community-edition=2.4.4
composer/magento/community-edition>=2.4.0<2.4.3-p3
composer/magento/community-edition>=2.3.0<2.3.7-p4
Adobe Commerce>=2.3.0<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
and 17 more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges c...
composer/magento/community-edition>=2.4.0<2.4.3-p3
composer/magento/community-edition>=2.4.4<2.4.5
composer/magento/community-edition<2.3.7-p4
Adobe Commerce>=2.3.0<2.3.7
Adobe Commerce>=2.4.0<2.4.3
Adobe Commerce=2.3.7
and 17 more
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source
composer/magento/community-edition>=2.4.0<2.4.3-p2
composer/magento/community-edition>=2.3.3-p1<2.3.7-p3
Adobe Commerce<2.3.0
Adobe Commerce>2.3.3<=2.3.6
Adobe Commerce>=2.4.0<=2.4.2
and 11 more
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful ex...
Adobe Commerce<=2.3.7
Adobe Commerce=2.3.7-p1
Adobe Commerce=2.4.2
Adobe Commerce=2.4.2-p1
Adobe Commerce=2.4.2-p2
Adobe Commerce=2.4.3
and 6 more

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203