Oracle commerce platform
This hub aggregates every CVE we track for Oracle commerce platform, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
3
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7CRITICAL3MEDIUM2
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
9
0
2024-092026-08
Latest CVEs
The 12 most recently published vulnerabilities affecting Oracle commerce platform.
- CVE-2026-61137Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerab...8.1
- CVE-2026-61136Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerabil...7.3
- CVE-2026-61133Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerabil...7.5
- CVE-2026-61135Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerab...7.4
- CVE-2026-61134Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerab...6.8
- CVE-2026-61130Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerabil...9.1
- CVE-2026-61132Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerabil...7.6
- CVE-2026-61131Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerabil...9.8
- CVE-2026-61129Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauth...9.8
- CVE-2025-21576Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exp...5.4
- CVE-2020-36518jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.7.5
- CVE-2021-40690Bypass of the secureValidation property7.5
Product normalization is registry-driven with AI assist and human review. How it works