Adobe

Commerce

147 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.07%
  • Published 14.08.2024 12:15:25
  • Last modified 14.08.2024 14:48:25

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an a...

  • EPSS 1.07%
  • Published 14.08.2024 12:15:25
  • Last modified 14.08.2024 14:45:28

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an a...

  • EPSS 1.01%
  • Published 14.08.2024 12:15:25
  • Last modified 14.08.2024 14:45:31

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Ma...

  • EPSS 0.13%
  • Published 14.08.2024 12:15:25
  • Last modified 14.08.2024 14:44:35

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass s...

  • EPSS 5.34%
  • Published 14.08.2024 12:15:24
  • Last modified 14.08.2024 14:46:52

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this v...

  • EPSS 0.09%
  • Published 14.08.2024 12:15:24
  • Last modified 14.08.2024 14:47:10

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a security feature bypass. An attacker could exploit this vulne...

  • EPSS 0.43%
  • Published 14.08.2024 12:15:24
  • Last modified 14.08.2024 14:47:39

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A low-privileged...

  • EPSS 0.71%
  • Published 14.08.2024 12:15:24
  • Last modified 14.08.2024 14:48:01

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker to inject and execute arbitrary JavaScript code within t...

  • EPSS 2.81%
  • Published 13.06.2024 09:15:13
  • Last modified 21.11.2024 09:18:07

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. A high-privilege attacker could exploit this vulne...

  • EPSS 0.23%
  • Published 13.06.2024 09:15:13
  • Last modified 21.11.2024 09:18:07

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application...