Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe Commerce — Vulnerabilities & Security Advisories 190

All 190 CVE vulnerabilities found in Adobe Commerce, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumerations associated with the Adobe Commerce product offered by Adobe. It specifically focuses on security vulnerabilities within this enterprise e-commerce platform to assist developers and security administrators in assessing risk. The content here collects a wide variety of vulnerability types, including but not limited to cross-site scripting, injection flaws, access control misconfigurations, and improper error handling mechanisms. These entries cover a broad time range, starting from the initial releases of the platform through to the most recently disclosed security issues, ensuring historical context is available alongside current threats. By utilizing this resource, users can effectively track vendor advisories issued by Adobe regarding critical patches and workarounds for their specific deployment environments. Furthermore, visitors can gain a deeper understanding of specific weakness classes prevalent in this software ecosystem, allowing for more targeted mitigation strategies and code reviews. The database also enables users to look up a product's vulnerability history, providing insight into how the software has evolved in response to security challenges over time. This holistic view supports informed decision-making for security audits and compliance reporting, helping organizations maintain robust defenses against known exploits without needing to consult fragmented sources.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2025-54236 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 9.1 Critical2025-09-09
CVE-2025-49556 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 7.5 High2025-08-12
CVE-2025-49557 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-08-12
CVE-2025-49558 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 5.9 Medium2025-08-12
CVE-2025-49554 Adobe Commerce | Improper Input Validation (CWE-20) CWE-20 7.5 High2025-08-12
CVE-2025-49559 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 5.3 Medium2025-08-12
CVE-2025-49555 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 8.1 High2025-08-12
CVE-2025-49550 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-06-25
CVE-2025-49549 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 2.7 Low2025-06-25
CVE-2025-27206 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-06-10
CVE-2025-43586 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 8.1 High2025-06-10
CVE-2025-47110 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.4 High2025-06-10
CVE-2025-27207 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-06-10
CVE-2025-43585 Adobe Commerce | Improper Authorization (CWE-285) CWE-285 8.2 High2025-06-10
CVE-2025-27190 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27191 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 5.3 Medium2025-04-08
CVE-2025-27192 Adobe Commerce | Insufficiently Protected Credentials (CWE-522) CWE-522 2.7 Low2025-04-08
CVE-2025-27188 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-04-08
CVE-2025-27189 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) CWE-352 4.3 Medium2025-04-08
CVE-2025-24422 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 6.5 Medium2025-02-11
CVE-2025-24414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24434 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 9.1 Critical2025-02-11
CVE-2025-24437 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 5.4 Medium2025-02-11
CVE-2025-24415 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24411 Adobe Commerce | Improper Access Control (CWE-284) CWE-284 8.1 High2025-02-11
CVE-2025-24416 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24420 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-02-11
CVE-2025-24419 Adobe Commerce | Incorrect Authorization (CWE-863) CWE-863 4.3 Medium2025-02-11
CVE-2025-24413 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 8.7 High2025-02-11
CVE-2025-24432 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) CWE-367 3.7 Low2025-02-11

All 190 known CVE vulnerabilities affecting Adobe Commerce with full Chinese analysis, references, and POCs where available.