Adobe Commerce
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*
- <= 2.4.9
- <= 2.4.8-p5
- <= 2.4.7-p10
- <= 2.4.6-p15
- <= 2.4.5-p17
- <= 2.4.4-p18
A SQL injection vulnerability has been identified in Adobe Commerce, specifically in versions 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier. This vulnerability arises from improper neutralization of special elements used in SQL commands, potentially allowing high-privileged attackers to execute malicious SQL commands. Exploitation of this vulnerability could lead to arbitrary code execution in the context of the current user, with elevated access or control over the victim's account or session. Notably, this vulnerability does not require user interaction.
Exploitation of this vulnerability could result in arbitrary code execution, allowing an attacker to execute malicious code on the server with the privileges of the affected user.
Users are advised to update to the latest versions of Adobe Commerce. The updated versions are 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, and 2.4.4-2026-jul. Instructions for updating can be found in the Adobe Commerce Release Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.