Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 169

All 169 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for Adobe Commerce, a popular e-commerce platform developed by Adobe Inc., categorized under various weakness types and security tags. The collection focuses on critical and high-severity issues affecting the product’s core functionality, extensions, and integrated components. It encompasses vulnerability data spanning from the early 2010s through the present, ensuring a comprehensive historical perspective alongside recent findings. The dataset includes issues related to remote code execution, cross-site scripting, SQL injection, and privilege escalation, reflecting the evolving threat landscape surrounding modern e-commerce architectures. Readers can track a vendor's advisories by following the chronological release notes and security bulletins published by Adobe. This structured approach allows users to understand a weakness class by analyzing patterns across different versions and modules of the software. Furthermore, individuals can look up a product's vulnerability history to assess long-term security trends and identify recurring problem areas. By centralizing this information, the page serves as a reference point for security professionals, developers, and system administrators who need to evaluate risk exposure. The content is organized to facilitate quick retrieval of relevant details without requiring extensive navigation. Users are encouraged to cross-reference this data with official patch notes and implementation guides to ensure accurate remediation. The goal is to provide a transparent and accessible resource for understanding the security posture of Adobe Commerce over time, supporting informed decision-making regarding updates and configuration hardening.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2024-45127 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2024-10-10
CVE-2024-45128 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.4 Medium2024-10-10
CVE-2024-45133 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-45124 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2024-10-10
CVE-2024-45123 Adobe Commerce | Cross-site Scripting (Reflected XSS) (CWE-79) CWE-79 6.1 Medium2024-10-10
CVE-2024-45121 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45117 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 7.6 High2024-10-10
CVE-2024-45115 Adobe Commerce | Improper Authentication (CWE-287) CWE-287 9.8 Critical2024-10-10
CVE-2024-45116 Adobe Commerce | Cross-site Scripting (XSS) (CWE-79) CWE-79 8.1 High2024-10-10
CVE-2024-45119 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 4.9 Medium2024-10-10
CVE-2024-45122 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45120 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 3.1 Low2024-10-10
CVE-2024-45135 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-45130 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45132 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium2024-10-10
CVE-2024-45148 Adobe Commerce | Improper Authentication (CWE-287) CWE-287 8.8 High2024-10-10
CVE-2024-45131 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.4 Medium2024-10-10
CVE-2024-45134 Adobe Commerce | Information Exposure (CWE-200) CWE-200 2.7 Low2024-10-10
CVE-2024-45129 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 4.3 Medium2024-10-10
CVE-2024-45118 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2024-10-10
CVE-2024-45125 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2024-10-10
CVE-2024-45149 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 2.7 Low2024-10-10
CVE-2024-39419 A user without ship permissions can ship the orders CWE-285 4.3 Medium2024-08-14
CVE-2024-39403 Stored XSS through Webhook module public key configuration CWE-79 7.6 High2024-08-14
CVE-2024-39418 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 5.4 Medium2024-08-14
CVE-2024-39413 An unauthorized user can export the Invoiced Sales Report CWE-285 4.3 Medium2024-08-14
CVE-2024-39408 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2024-08-14
CVE-2024-39399 [Paris] Path Traversal lead to local file read CWE-22 7.7 High2024-08-14
CVE-2024-39417 An unauthorized user can export the Shipping Report CWE-285 4.3 Medium2024-08-14
CVE-2024-39410 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2024-08-14

All 169 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.