Vulnerabilities > Adobe > Commerce > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-10-14 CVE-2022-35698 Cross-site Scripting vulnerability in Adobe Commerce and Magento Open Source
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability.
network
low complexity
adobe CWE-79
5.4
2022-08-19 CVE-2022-35692 Unspecified vulnerability in Adobe Commerce and Magento Commerce
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.
network
low complexity
adobe
5.3
2022-08-16 CVE-2022-34257 Cross-site Scripting vulnerability in multiple products
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe magento CWE-79
6.1
2022-08-16 CVE-2022-34258 Cross-site Scripting vulnerability in multiple products
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe magento CWE-79
4.8
2022-08-16 CVE-2022-34259 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.
network
low complexity
adobe magento
5.3
2021-10-15 CVE-2021-39864 Cross-Site Request Forgery (CSRF) vulnerability in Adobe Commerce and Magento Open Source
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link.
network
adobe CWE-352
4.3