CVE-2025-49559
- EPSS 0.26%
- Veröffentlicht 12.08.2025 18:15:29
- Zuletzt bearbeitet 15.08.2025 15:40:55
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feat...
CVE-2025-49554
- EPSS 0.24%
- Veröffentlicht 12.08.2025 18:15:28
- Zuletzt bearbeitet 15.08.2025 15:37:34
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerab...
CVE-2025-49550
- EPSS 0.07%
- Veröffentlicht 25.06.2025 17:41:58
- Zuletzt bearbeitet 24.07.2025 19:20:44
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass secu...
CVE-2025-49549
- EPSS 0.07%
- Veröffentlicht 25.06.2025 17:41:13
- Zuletzt bearbeitet 24.07.2025 19:20:37
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability...
CVE-2025-47110
- EPSS 0.08%
- Veröffentlicht 10.06.2025 16:15:41
- Zuletzt bearbeitet 15.07.2025 18:40:20
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form...
CVE-2025-43586
- EPSS 0.07%
- Veröffentlicht 10.06.2025 16:15:40
- Zuletzt bearbeitet 23.06.2025 19:22:26
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to by...
CVE-2025-43585
- EPSS 0.08%
- Veröffentlicht 10.06.2025 16:15:40
- Zuletzt bearbeitet 23.06.2025 19:22:41
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass secur...
CVE-2025-27206
- EPSS 0.1%
- Veröffentlicht 10.06.2025 16:15:36
- Zuletzt bearbeitet 23.06.2025 19:25:38
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass secu...
CVE-2025-27207
- EPSS 0.07%
- Veröffentlicht 10.06.2025 16:15:36
- Zuletzt bearbeitet 11.07.2025 16:42:26
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to by...
CVE-2025-27190
- EPSS 0.12%
- Veröffentlicht 08.04.2025 20:17:12
- Zuletzt bearbeitet 23.06.2025 19:30:03
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass...