Adobe / Adobe Commerce B2b
64 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48001 | Adobe Commerce | Information Exposure (CWE-200) | LOW | 3.7 | Jul 14, 2026 |
| CVE-2026-48371 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | MEDIUM | 5.4 | Jul 14, 2026 |
| CVE-2026-47996 | Adobe Commerce | Incorrect Authorization (CWE-863) | MEDIUM | 6.8 | Jul 14, 2026 |
| CVE-2026-47994 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | HIGH | 8.7 | Jul 14, 2026 |
| CVE-2026-47992 | Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) | HIGH | 7.2 | Jul 14, 2026 |
| CVE-2026-34656 | Adobe Commerce | Improper Authorization (CWE-285) | MEDIUM | 4.3 | May 12, 2026 |
| CVE-2026-34658 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | MEDIUM | 4.8 | May 12, 2026 |
| CVE-2026-34650 | Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-34686 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | HIGH | 8.7 | May 12, 2026 |
| CVE-2026-34647 | Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) | HIGH | 7.4 | May 12, 2026 |
| CVE-2026-34685 | Adobe Commerce | Improper Input Validation (CWE-20) | LOW | 3.4 | May 12, 2026 |
| CVE-2026-34653 | Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | HIGH | 8.7 | May 12, 2026 |
| CVE-2026-34652 | Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-34645 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-34648 | Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-34649 | Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-34655 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | MEDIUM | 4.8 | May 12, 2026 |
| CVE-2026-34654 | Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) | MEDIUM | 5.3 | May 12, 2026 |
| CVE-2026-34651 | Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-34646 | Adobe Commerce | Incorrect Authorization (CWE-863) | HIGH | 7.5 | May 12, 2026 |
| CVE-2026-21291 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | MEDIUM | 4.8 | Mar 11, 2026 |
| CVE-2026-21293 | Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) | MEDIUM | 5.5 | Mar 11, 2026 |
| CVE-2026-21282 | Adobe Commerce | Improper Input Validation (CWE-20) | MEDIUM | 5.3 | Mar 11, 2026 |
| CVE-2026-21286 | Adobe Commerce | Incorrect Authorization (CWE-863) | MEDIUM | 5.3 | Mar 11, 2026 |
| CVE-2026-21294 | Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) | MEDIUM | 5.5 | Mar 11, 2026 |
Showing 26 to 50 of 64 CVEs