Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 190

All 190 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumerations associated with the Adobe Commerce product offered by Adobe. It specifically focuses on security vulnerabilities within this enterprise e-commerce platform to assist developers and security administrators in assessing risk. The content here collects a wide variety of vulnerability types, including but not limited to cross-site scripting, injection flaws, access control misconfigurations, and improper error handling mechanisms. These entries cover a broad time range, starting from the initial releases of the platform through to the most recently disclosed security issues, ensuring historical context is available alongside current threats. By utilizing this resource, users can effectively track vendor advisories issued by Adobe regarding critical patches and workarounds for their specific deployment environments. Furthermore, visitors can gain a deeper understanding of specific weakness classes prevalent in this software ecosystem, allowing for more targeted mitigation strategies and code reviews. The database also enables users to look up a product's vulnerability history, providing insight into how the software has evolved in response to security challenges over time. This holistic view supports informed decision-making for security audits and compliance reporting, helping organizations maintain robust defenses against known exploits without needing to consult fragmented sources.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2026-34648 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High2026-05-12
CVE-2026-34649 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High2026-05-12
CVE-2026-34655 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2026-05-12
CVE-2026-34651 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) CWE-400 7.5 High2026-05-12
CVE-2026-34654 Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) CWE-1395 5.3 Medium2026-05-12
CVE-2026-34646 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2026-05-12
CVE-2026-21291 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2026-03-11
CVE-2026-21293 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 5.5 Medium2026-03-11
CVE-2026-21282 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 5.3 Medium2026-03-11
CVE-2026-21286 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.3 Medium2026-03-11
CVE-2026-21294 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 5.5 Medium2026-03-11
CVE-2026-21284 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2026-03-11
CVE-2026-21297 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2026-03-11
CVE-2026-21359 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.7 Medium2026-03-11
CVE-2026-21309 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2026-03-11
CVE-2026-21292 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 5.4 Medium2026-03-11
CVE-2026-21310 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 5.3 Medium2026-03-11
CVE-2026-21285 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2026-03-11
CVE-2026-21290 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2026-03-11
CVE-2026-21361 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2026-03-11
CVE-2026-21289 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2026-03-11
CVE-2026-21360 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 6.8 Medium2026-03-11
CVE-2026-21296 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2026-03-11
CVE-2026-21311 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.0 High2026-03-11
CVE-2026-21295 Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) CWE-601 3.1 Low2026-03-11
CVE-2025-54267 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 6.5 Medium2025-10-14
CVE-2025-54266 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2025-10-14
CVE-2025-54263 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 8.1 High2025-10-14
CVE-2025-54264 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.1 High2025-10-14
CVE-2025-54265 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.9 Medium2025-10-14

All 190 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.