Adobe Commerce
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*
- <= 2.4.9
- <= 2.4.8-p5
- <= 2.4.7-p10
- <= 2.4.6-p15
- <= 2.4.5-p17
- <= 2.4.4-p18
A vulnerability allowing arbitrary code execution through improper encoding or escaping of output has been identified in Adobe Commerce. This issue affects several versions, including 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier. The vulnerability also impacts Adobe Commerce B2B versions 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier. Additionally, it affects Magento Open Source versions 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, and 2.4.6-p15 and earlier. The vulnerability is present in Adobe Commerce Events versions 1.6.0 to 1.20.0. Exploitation of this vulnerability does not require user interaction and could result in arbitrary code execution in the context of the current user.
Successful exploitation of this vulnerability could lead to arbitrary code execution.
Users are advised to update to the latest versions of Adobe Commerce, Adobe Commerce B2B, Magento Open Source, or Adobe Commerce Events. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.