Adobe commerce
This hub aggregates every CVE we track for Adobe commerce, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
235
CVEs tracked
29
Critical
81
High
3
In CISA KEV
Severity distribution
MEDIUM111HIGH81CRITICAL29LOW14
Monthly trend
1
22
1
0
0
31
0
5
0
7
0
6
1
5
0
0
0
0
19
0
15
0
14
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Adobe commerce.
- CVE-2026-47984Adobe Commerce | Incorrect Authorization (CWE-863)8.2
- CVE-2026-47997Adobe Commerce | Incorrect Authorization (CWE-863)5.9
- CVE-2026-47988Adobe Commerce | Incorrect Authorization (CWE-863)8.6
- CVE-2026-47999Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)4.8
- CVE-2026-48358Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)9.1
- CVE-2026-48356Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)9.3
- CVE-2026-47998Adobe Commerce | Incorrect Authorization (CWE-863)5.9
- CVE-2026-48000Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)6.1
- CVE-2026-47995Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)8.1
- CVE-2026-48001Adobe Commerce | Information Exposure (CWE-200)3.7
- CVE-2026-48371Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)5.4
- CVE-2026-47994Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)8.7
- CVE-2026-47996Adobe Commerce | Incorrect Authorization (CWE-863)6.8
- CVE-2026-47992Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)7.2
- CVE-2026-34656Adobe Commerce | Improper Authorization (CWE-285)4.3
Product normalization is registry-driven with AI assist and human review. How it works