Adobe / Adobe Commerce
199 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-76200 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | CRITICAL | 9.3 | Sep 8, 2026 |
| CVE-2026-76201 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | CRITICAL | 9.3 | Sep 8, 2026 |
| CVE-2026-77109 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 8.6 | Sep 8, 2026 |
| CVE-2026-77110 | Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | HIGH | 7.6 | Sep 8, 2026 |
| CVE-2026-77108 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 7.5 | Sep 8, 2026 |
| CVE-2026-76202 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 8.2 | Sep 8, 2026 |
| CVE-2026-77774 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 8.6 | Sep 8, 2026 |
| CVE-2026-77111 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 8.7 | Sep 8, 2026 |
| CVE-2026-75650 KEV | Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) | CRITICAL | 10.0 | Sep 7, 2026 |
| CVE-2026-48414 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | HIGH | 7.7 | Aug 11, 2026 |
| CVE-2026-48416 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 7.5 | Aug 11, 2026 |
| CVE-2026-48413 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | HIGH | 8.7 | Aug 11, 2026 |
| CVE-2026-48415 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 7.6 | Aug 11, 2026 |
| CVE-2026-48412 | Adobe Commerce | Incorrect Authorization (CWE-863) | LOW | 2.7 | Aug 11, 2026 |
| CVE-2026-48411 | Adobe Commerce | Incorrect Authorization (CWE-863) | MEDIUM | 6.5 | Aug 11, 2026 |
| CVE-2026-71362 KEV | Adobe Commerce | Incorrect Authorization (CWE-863) | CRITICAL | 9.1 | Aug 11, 2026 |
| CVE-2026-47984 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 8.2 | Jul 14, 2026 |
| CVE-2026-47997 | Adobe Commerce | Incorrect Authorization (CWE-863) | MEDIUM | 5.9 | Jul 14, 2026 |
| CVE-2026-47988 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 8.6 | Jul 14, 2026 |
| CVE-2026-47999 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | MEDIUM | 4.8 | Jul 14, 2026 |
| CVE-2026-48358 | Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) | CRITICAL | 9.1 | Jul 14, 2026 |
| CVE-2026-48356 | Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) | CRITICAL | 9.3 | Jul 14, 2026 |
| CVE-2026-47998 | Adobe Commerce | Incorrect Authorization (CWE-863) | MEDIUM | 5.9 | Jul 14, 2026 |
| CVE-2026-48000 | Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) | MEDIUM | 6.1 | Jul 14, 2026 |
| CVE-2026-47995 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | HIGH | 8.1 | Jul 14, 2026 |
Showing 1 to 25 of 199 CVEs