magento/community-edition
Packagist353 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting magento/community-editionpage 7 of 8
- CVE-2024-45129MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to …
- CVE-2024-45130MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerabilit…
- CVE-2024-45131MEDIUMCVSS 5.4EG 5.4fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability…
- CVE-2024-45132MEDIUMCVSS 6.5EG 6.5fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to b…
- CVE-2024-45133LOWCVSS 2.7EG 2.7fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a…
- CVE-2024-45134LOWCVSS 2.7EG 2.7fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a…
- CVE-2024-45135LOWCVSS 2.7EG 2.7fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to byp…
- CVE-2024-45149LOWCVSS 2.7EG 2.7fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerabili…
- CVE-2025-24406HIGHCVSS 7.5EG 7.5fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature…
- CVE-2025-24408MEDIUMCVSS 6.5EG 6.5fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized ac…
- CVE-2025-24409HIGHCVSS 8.2EG 8.2fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabili…
- CVE-2025-24410HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24411HIGHCVSS 8.1EG 8.1fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage thi…
- CVE-2025-24412HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24413HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24414HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24415HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24416HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24417HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24421MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this…
- CVE-2025-24424MEDIUMCVSS 6.5EG 6.5fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage thi…
- CVE-2025-24425MEDIUMCVSS 5.3EG 5.3fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to …
- CVE-2025-24427MEDIUMCVSS 6.5EG 6.5fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage thi…
- CVE-2025-24428MEDIUMCVSS 5.4EG 5.4fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-24429LOWCVSS 3.5EG 3.5fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged a…
- CVE-2025-24430LOWCVSS 3.7EG 3.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could e…
- CVE-2025-24432LOWCVSS 3.7EG 3.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could e…
- CVE-2025-24434CRITICALCVSS 9.1EG 9.1fixed in 2.4.8-beta2, 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 0.1.0-alpha100 ... 2.4.4-p9 (149 versions)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to …
- CVE-2025-24435MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p4, 2.4.6-p9, 2.4.4-p12 or 2.4.5-p11, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vul…
- CVE-2025-24436MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this…
- CVE-2025-24437MEDIUMCVSS 5.4EG 5.4fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this…
- CVE-2025-24438HIGHCVSS 8.7EG 8.7fixed in 2.4.7-p4, 2.4.6-p9, 2.4.5-p11 or 2.4.4-p12, by version range2025-02-11
vulnerable: 2.4.8-beta1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …
- CVE-2025-27188MEDIUMCVSS 4.3EG 4.3fixed in 2.4.4-p13, 2.4.5-p12, 2.4.6-p10, 2.4.7-p5 or 2.4.8, by version range2025-04-08
vulnerable: 2.4.8-beta1, 2.4.8-beta2
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to b…
- CVE-2025-27190MEDIUMCVSS 5.3EG 5.3fixed in 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 or 2.4.8-beta2, by version range2025-04-08
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabilit…
- CVE-2025-27191MEDIUMCVSS 5.3EG 5.3fixed in 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 or 2.4.8-beta2, by version range2025-04-08
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabilit…
- CVE-2025-27192LOWCVSS 2.7EG 2.7fixed in 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 or 2.4.8-beta2, by version range2025-04-08
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could …
- CVE-2025-27206MEDIUMCVSS 5.3EG 5.3fixed in 2.4.7-p6, 2.4.6-p11 or 2.4.5-p13, by version range2025-06-10
vulnerable: 2.4.8
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to …
- CVE-2025-43585HIGHCVSS 8.2EG 8.2fixed in 2.4.7-p6, 2.4.6-p11 or 2.4.5-p13, by version range2025-06-10
vulnerable: 2.4.8
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to b…
- CVE-2025-47110HIGHCVSS 8.4EG 8.4fixed in 2.4.8-p1, 2.4.7-p6, 2.4.5-p13 or 2.4.6-p11, by version range2025-06-10
vulnerable: 2.4.6
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vuln…
- CVE-2025-49549LOWCVSS 2.7EG 2.7fixed in 2.4.7-p6, 2.4.6-p11 or 2.4.5-p13, by version range2025-06-25
vulnerable: 2.4.8
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vu…
- CVE-2025-49550MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p6, 2.4.6-p11 or 2.4.5-p13, by version range2025-06-25
vulnerable: 2.4.8
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to …
- CVE-2025-49554HIGHCVSS 7.5EG 7.5fixed in 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12 or 2.4.5-p14, by version range2025-08-12
vulnerable: 2.4.8
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit th…
- CVE-2025-49555HIGHCVSS 8.1EG 8.1fixed in 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12 or 2.4.5-p14, by version range2025-08-12
vulnerable: 2.4.8
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker c…
- CVE-2025-49556HIGHCVSS 7.5EG 7.5fixed in 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12 or 2.4.5-p14, by version range2025-08-12
vulnerable: 2.4.8
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this …
- CVE-2025-49557HIGHCVSS 8.7EG 8.7fixed in 2.4.4-p15, 2.4.5-p14, 2.4.6-p12 or 2.4.7-p7, by version range2025-08-12
vulnerable: 2.4.8
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be exploited by a low-privileged attacker to inject maliciou…
- CVE-2025-49558MEDIUMCVSS 5.9EG 5.9fixed in 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12 or 2.4.5-p14, by version range2025-08-12
vulnerable: 2.4.8
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An atta…
- CVE-2025-49559MEDIUMCVSS 5.3EG 5.3fixed in 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12 or 2.4.5-p14, by version range2025-08-12
vulnerable: 2.4.8
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a se…
- CVE-2025-54236CRITICALCVSS 9.1EG 9.1⚠ KEV2025-09-09
vulnerable: 2.4.9
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing …
- CVE-2025-54263HIGHCVSS 8.1EG 8.1fixed in 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8 or 2.4.6-p13, by version range2025-10-14
vulnerable: 2.4.6
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security …
- CVE-2025-54264HIGHCVSS 8.1EG 8.1fixed in 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8 or 2.4.6-p13, by version range2025-10-14
vulnerable: 2.4.6
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged at…
Check whether magento/community-edition is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for magento/community-edition CVEs against the assets you own.
Book a Demo →