Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Adobe Commerce — Vulnerabilities & Security Advisories 169

All 169 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of common weakness vulnerabilities associated with Adobe Commerce, a leading e-commerce platform. It collects security issues affecting the software’s core functionalities, extensions, and integrations, covering incidents reported from January 2018 to the present. By consolidating this data, the page allows users to track vendor advisories as they are released, ensuring that administrators can stay informed about emerging threats and required patches. Visitors can also dive deeper into specific weakness classes, such as cross-site scripting or SQL injection, to understand the underlying mechanics and potential impact on their deployment environments. Additionally, the resource enables users to look up a product's vulnerability history, providing a longitudinal view of security trends and the effectiveness of historical remediation efforts. This structured approach helps security professionals evaluate the risk profile of Adobe Commerce installations over time, facilitating more informed decision-making regarding upgrade paths and mitigation strategies. The aggregation process ensures that fragmented data from multiple sources is unified into a single, accessible reference point, reducing the manual effort required to monitor security updates. By focusing on factual reporting and historical context, this page serves as a practical tool for maintaining the integrity and stability of Adobe Commerce deployments without bias or promotional content.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2026-34656 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 4.3 Medium2026-05-12
CVE-2026-34650 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High2026-05-12
CVE-2026-34658 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2026-05-12
CVE-2026-34686 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2026-05-12
CVE-2026-34647 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 7.4 High2026-05-12
CVE-2026-34685 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 3.4 Low2026-05-12
CVE-2026-34653 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 8.7 High2026-05-12
CVE-2026-34652 Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) CWE-1395 7.5 High2026-05-12
CVE-2026-34645 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2026-05-12
CVE-2026-34648 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High2026-05-12
CVE-2026-34649 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High2026-05-12
CVE-2026-34655 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2026-05-12
CVE-2026-34651 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High2026-05-12
CVE-2026-34654 Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) CWE-1395 5.3 Medium2026-05-12
CVE-2026-34646 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2026-05-12
CVE-2026-21291 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2026-03-11
CVE-2026-21293 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 5.5 Medium2026-03-11
CVE-2026-21282 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 5.3 Medium2026-03-11
CVE-2026-21286 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.3 Medium2026-03-11
CVE-2026-21294 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 5.5 Medium2026-03-11
CVE-2026-21284 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2026-03-11
CVE-2026-21297 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2026-03-11
CVE-2026-21359 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.7 Medium2026-03-11
CVE-2026-21309 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2026-03-11
CVE-2026-21292 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 5.4 Medium2026-03-11
CVE-2026-21310 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 5.3 Medium2026-03-11
CVE-2026-21285 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2026-03-11
CVE-2026-21290 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2026-03-11
CVE-2026-21361 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2026-03-11
CVE-2026-21289 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2026-03-11

All 169 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.