Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 169

All 169 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of common weakness vulnerabilities associated with Adobe Commerce, a leading e-commerce platform. It collects security issues affecting the software’s core functionalities, extensions, and integrations, covering incidents reported from January 2018 to the present. By consolidating this data, the page allows users to track vendor advisories as they are released, ensuring that administrators can stay informed about emerging threats and required patches. Visitors can also dive deeper into specific weakness classes, such as cross-site scripting or SQL injection, to understand the underlying mechanics and potential impact on their deployment environments. Additionally, the resource enables users to look up a product's vulnerability history, providing a longitudinal view of security trends and the effectiveness of historical remediation efforts. This structured approach helps security professionals evaluate the risk profile of Adobe Commerce installations over time, facilitating more informed decision-making regarding upgrade paths and mitigation strategies. The aggregation process ensures that fragmented data from multiple sources is unified into a single, accessible reference point, reducing the manual effort required to monitor security updates. By focusing on factual reporting and historical context, this page serves as a practical tool for maintaining the integrity and stability of Adobe Commerce deployments without bias or promotional content.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2026-21360 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 6.8 Medium2026-03-11
CVE-2026-21296 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2026-03-11
CVE-2026-21311 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.0 High2026-03-11
CVE-2026-21295 Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) CWE-601 3.1 Low2026-03-11
CVE-2025-54267 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium2025-10-14
CVE-2025-54266 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2025-10-14
CVE-2025-54263 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 8.1 High2025-10-14
CVE-2025-54265 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.9 Medium2025-10-14
CVE-2025-54264 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2025-10-14
CVE-2025-54236 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 9.1 Critical2025-09-09
CVE-2025-49556 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2025-08-12
CVE-2025-49557 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-08-12
CVE-2025-49558 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 5.9 Medium2025-08-12
CVE-2025-49554 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 7.5 High2025-08-12
CVE-2025-49559 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 5.3 Medium2025-08-12
CVE-2025-49555 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 8.1 High2025-08-12
CVE-2025-49550 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-06-25
CVE-2025-49549 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 2.7 Low2025-06-25
CVE-2025-27206 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-06-10
CVE-2025-43586 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 8.1 High2025-06-10
CVE-2025-47110 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.4 High2025-06-10
CVE-2025-27207 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-06-10
CVE-2025-43585 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 8.2 High2025-06-10
CVE-2025-27190 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27192 Adobe Commerce | Insufficiently Protected Credentials (CWE-522) CWE-522 2.7 Low2025-04-08
CVE-2025-27191 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27188 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-04-08
CVE-2025-27189 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2025-04-08
CVE-2025-24422 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-02-11
CVE-2025-24414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11

All 169 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.