Evidence dossier

CVE-2025-54236

Adobe Commerce | Improper Input Validation (CWE-20)

Exploited in the wild (CISA KEV since Oct 24, 2025). adobe reports CVSS 3.1 9.1. EPSS estimates 96.7% exploit likelihood as of Jul 26, 2026.

86.687.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

State
PUBLISHED
Published
Sep 9, 2025
Updated
Oct 24, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    adobe

    Record text: Adobe Commerce | Improper Input Validation (CWE-20)

    Inspect raw assertion
    Field
    container
    Value
    Adobe Commerce | Improper Input Validation (CWE-20)
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Adobe Commerce and Magento Improper Input Validation Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Adobe Commerce and Magento Improper Input Validation Vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 96.74% probability · 99.88th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.967420000000; percentile 0.998820000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Oct 24, 2025 · first observed Jul 19, 2026

Exploit likelihood96.74%

FIRST EPSS · score date Jul 26, 2026 · 99.9th percentile · first observed Jul 27, 2026

SeverityCVSS 9.1

adobe · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

adobeOriginal assertion
Record text

Adobe Commerce | Improper Input Validation (CWE-20)

Inspect raw assertion
Field
container
Value
Adobe Commerce | Improper Input Validation (CWE-20)
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Adobe Commerce and Magento Improper Input Validation Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Adobe Commerce and Magento Improper Input Validation Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

96.74% probability · 99.88th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.967420000000; percentile 0.998820000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
152Underlying assertions
3Canonical products
152Target assertions
0Constraint assertions

Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

4 scope groups

adobe · source assertedAdobeAdobe CommerceDirect source scope
Affected: 0 through 2.4.4-p15 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "2.4.4-p15"}]
NVD CPE · APPLICATIONadobecommerceVulnerable target · 62 assertions
Version 2.4.4; Version 2.4.5; Version 2.4.6; Version 2.4.7; Version 2.4.8; Version 2.4.9Canonical identity product-4f9e417403ee5779da342a16f6238abe5aac2ea26bd39a70bbc320fef7d3fb73Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:adobe:commerce:2.4.9:alpha2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8b6b7609-6a8e-4154-bc05-2a9099909684
  2. cpe:2.3:a:adobe:commerce:2.4.4:p8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8867f510-201c-4199-8554-53de156ce669
  3. cpe:2.3:a:adobe:commerce:2.4.7:b1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6ebb0608-034b-4f07-a59b-9e6a989ba260
  4. cpe:2.3:a:adobe:commerce:2.4.4:p9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    23988132-dd4e-4968-b6b8-954122f76081
  5. cpe:2.3:a:adobe:commerce:2.4.5:p9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    898a8679-3c46-4718-9edf-583addfcf2ec
  6. cpe:2.3:a:adobe:commerce:2.4.6:p11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    47a86566-de38-4032-947d-b6181f0bc120
  7. cpe:2.3:a:adobe:commerce:2.4.4:p13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    91736e79-d8e7-4af2-8e01-a7b4eb8ad6f4
  8. cpe:2.3:a:adobe:commerce:2.4.7:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2e05341a-c70c-4b3d-af30-9520d6b97d30
  9. cpe:2.3:a:adobe:commerce:2.4.5:p12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b044f2d9-e888-4852-8a40-dce688860ed3
  10. cpe:2.3:a:adobe:commerce:2.4.8:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b4947c63-cfd9-437b-a09e-a197dce40095
  11. cpe:2.3:a:adobe:commerce:2.4.5:p8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    952787c6-9bf1-49fb-9824-1236678e1902
  12. cpe:2.3:a:adobe:commerce:2.4.9:alpha1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    37f32f70-7b2a-4bab-b3f0-aff5c04ccded
  13. cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d258d9ef-94fb-41f0-a7a5-7f66fa7a0055
  14. cpe:2.3:a:adobe:commerce:2.4.6:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a576b1b5-73a2-431e-998f-7e5458b51d6a
  15. cpe:2.3:a:adobe:commerce:2.4.5:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8922d646-1a97-47ed-91c6-5a426781c98a
  16. cpe:2.3:a:adobe:commerce:2.4.4:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6d6f1a7-abb5-4edc-9ea8-98b74518847a
  17. cpe:2.3:a:adobe:commerce:2.4.7:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5d04853-0c2f-47dd-a939-3a8f6e22cb7d
  18. cpe:2.3:a:adobe:commerce:2.4.5:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9b07f7b2-e915-4eff-8ffc-91143cef082e
  19. cpe:2.3:a:adobe:commerce:2.4.6:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e05f4ac-2a28-47e3-96de-0e31af73cd43
  20. cpe:2.3:a:adobe:commerce:2.4.4:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6a56e96c-6ce5-442c-aa88-f0059b02b5e7
  21. cpe:2.3:a:adobe:commerce:2.4.5:p10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5764cc97-c866-415d-a3a1-5b5b9e1c06a6
  22. cpe:2.3:a:adobe:commerce:2.4.7:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4d98b52e-3b59-4327-ac7e-ddbb0ada08f6
  23. cpe:2.3:a:adobe:commerce:2.4.4:p11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    68aae162-5957-42af-be20-40f341837fac
  24. cpe:2.3:a:adobe:commerce:2.4.8:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c267af14-7ba8-4d1f-bcd9-be3ed0da3d25
  25. cpe:2.3:a:adobe:commerce:2.4.7:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3f1439ce-8a3b-414a-b974-559209ff480c
  26. cpe:2.3:a:adobe:commerce:2.4.5:p14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3472064a-8c79-436b-965a-96834ae8d346
  27. cpe:2.3:a:adobe:commerce:2.4.6:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e58690f9-fa9c-42a0-b4cd-91fd1197a53e
  28. cpe:2.3:a:adobe:commerce:2.4.4:p10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1c3d7164-1c5f-40bc-9eec-b0e00cd45808
  29. cpe:2.3:a:adobe:commerce:2.4.7:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    95026aa9-a28b-4d94-bd77-7628429eba30
  30. cpe:2.3:a:adobe:commerce:2.4.5:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7f5e9db6-1386-4274-8270-2fe0f0caf7fd
  31. cpe:2.3:a:adobe:commerce:2.4.7:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    83fd1220-7d46-42b2-8110-30a934144572
  32. cpe:2.3:a:adobe:commerce:2.4.5:p11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e82d10d8-2894-4e5b-b47b-f00964dd5cde
  33. cpe:2.3:a:adobe:commerce:2.4.5:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8605e4e6-0f7d-42c8-b35b-2349a0befc69
  34. cpe:2.3:a:adobe:commerce:2.4.4:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cfebddf2-6443-4482-83b2-3cd272cf599f
  35. cpe:2.3:a:adobe:commerce:2.4.5:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6df0e74d-9293-4209-97d1-a3ba13c3dde9
  36. cpe:2.3:a:adobe:commerce:2.4.8:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ee12f4b-5607-4790-a29b-ee23383bcc1a
  37. cpe:2.3:a:adobe:commerce:2.4.4:p15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bbda2bcf-e784-4cf3-b30d-6ff5bee2055f
  38. cpe:2.3:a:adobe:commerce:2.4.4:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4e5cf6f0-2388-4d3f-8fe1-43b8af148564
  39. cpe:2.3:a:adobe:commerce:2.4.5:p13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6423c754-36f9-4680-9211-60940ed63e79
  40. cpe:2.3:a:adobe:commerce:2.4.4:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    69a1f1f7-e53c-40f3-b3d9-dc011fc353bf
  41. cpe:2.3:a:adobe:commerce:2.4.4:p14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8412c043-64e7-4dff-a303-13a6fe113bfb
  42. cpe:2.3:a:adobe:commerce:2.4.4:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2515da6d-2e74-4a05-bd29-feef3322bcb6
  43. cpe:2.3:a:adobe:commerce:2.4.6:p10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e57889cc-3e90-46af-9cd6-3328dd501ad1
  44. cpe:2.3:a:adobe:commerce:2.4.8:beta2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c9e12b43-ad3e-48a2-9042-5586186ca3be
  45. cpe:2.3:a:adobe:commerce:2.4.4:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6661093f-8d22-450f-bc6c-a8894a52e6a9
  46. cpe:2.3:a:adobe:commerce:2.4.6:p12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b7d1d684-ce7e-4d6d-95b5-1f86a8db6c66
  47. cpe:2.3:a:adobe:commerce:2.4.5:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    324a573e-dbc8-42a0-8cb8-edd8fbab7115
  48. cpe:2.3:a:adobe:commerce:2.4.6:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6086841-c175-46a1-8414-71c6163a0e7a
  49. cpe:2.3:a:adobe:commerce:2.4.8:beta1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6d05a958-9749-486a-a149-c21647cdcadf
  50. cpe:2.3:a:adobe:commerce:2.4.7:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a9443ce-ae1f-4d66-9c88-5e2e3fd28ee6
  51. cpe:2.3:a:adobe:commerce:2.4.6:p9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    73d22d42-646d-4955-a6f9-9b7ba63dc0a9
  52. cpe:2.3:a:adobe:commerce:2.4.6:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    77d01d8b-1fbc-43ca-90f9-c89d9b4d18f0
  53. cpe:2.3:a:adobe:commerce:2.4.7:b2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3bf9b08-84e3-4974-9deb-f4285995d796
  54. cpe:2.3:a:adobe:commerce:2.4.5:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b6318f97-e59a-4425-8dc7-045c78a644f8
  55. cpe:2.3:a:adobe:commerce:2.4.6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c7afbb1-f9c9-4bde-bcef-94c9f0ac6798
  56. cpe:2.3:a:adobe:commerce:2.4.6:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d2e0ddd1-0f4a-4f96-b25d-40a39a1a535a
  57. cpe:2.3:a:adobe:commerce:2.4.6:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3a9a62ee-1649-4815-8ec9-7aef7949eb2f
  58. cpe:2.3:a:adobe:commerce:2.4.6:p8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8b83729e-80af-47ce-a70c-32bf83024a40
  59. cpe:2.3:a:adobe:commerce:2.4.5:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    54151a00-cfb8-4e6a-8e74-497cb67bf7e2
  60. cpe:2.3:a:adobe:commerce:2.4.4:p12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d9d01159-3309-4f6b-93b0-2d89ddd33dee
  61. cpe:2.3:a:adobe:commerce:2.4.7:beta3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7771bedb-05e2-430e-b2a2-e2f7574b7114
  62. cpe:2.3:a:adobe:commerce:2.4.7:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    13726dee-ffcb-447b-9fff-136f132f2c4c
NVD CPE · APPLICATIONadobecommerce_b2bVulnerable target · 44 assertions
Version 1.3.3; Version 1.3.4; Version 1.4.2; Version 1.5.2; Version 1.5.3Canonical identity product-a01cc59c643651344c827889139e76356339432d7d75c6ff3803ae5fa66a7c00Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6f220229-f2df-4c9d-90a6-8b09f8be3391
  2. cpe:2.3:a:adobe:commerce_b2b:1.4.2:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb863404-a9d7-4692-ab43-08945e669928
  3. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e396fb4f-b20a-4bf9-8fbd-014a0f197f08
  4. cpe:2.3:a:adobe:commerce_b2b:1.4.2:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a21f608c-c356-47b8-8fbb-db28babfc4c6
  5. cpe:2.3:a:adobe:commerce_b2b:1.3.4:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1c90c433-6655-4038-9ab3-0304c1aff360
  6. cpe:2.3:a:adobe:commerce_b2b:1.4.2:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9c360ea8-b18f-4327-90ef-7eed2892be4f
  7. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e5acaba-d6d6-4f29-a9dd-5a04a44abe64
  8. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6fe364a8-4780-426f-9e8a-284a31fe2623
  9. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f2c525d2-837d-486a-8b38-5634ae2ece2b
  10. cpe:2.3:a:adobe:commerce_b2b:1.5.3:alpha2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4d7c6592-33b0-4586-8178-e8f4eb837b7f
  11. cpe:2.3:a:adobe:commerce_b2b:1.3.3:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c4667aa3-4cc9-41c0-8e0c-19b0fce1cf79
  12. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f51dfa17-1875-41a9-b141-d89bb6238b3f
  13. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5cd0dc76-7181-4954-a59e-ab7bb47d0576
  14. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5d0a17ac-d433-47c2-a1ac-88291dcceccd
  15. cpe:2.3:a:adobe:commerce_b2b:1.4.2:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d8cfa8f4-d57d-4d0f-88d5-00a72e3ad8da
  16. cpe:2.3:a:adobe:commerce_b2b:1.5.3:alpha1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    508ee0ef-d54a-4834-84ab-ffc62040fdab
  17. cpe:2.3:a:adobe:commerce_b2b:1.4.2:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e14195f1-5016-46be-a614-6fb4e312fc93
  18. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51b76658-ea6b-4ac9-9d9c-374c5308d069
  19. cpe:2.3:a:adobe:commerce_b2b:1.4.2:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ed6ffc1d-e921-4ff7-9928-015630613fe1
  20. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    63ab9506-3f8e-4c2e-a859-2380431c15a6
  21. cpe:2.3:a:adobe:commerce_b2b:1.5.2:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d855d141-7876-4f5a-91be-6350dd379879
  22. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5a4d10ef-9137-4df5-a5dd-97907e8b4c02
  23. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa80afce-2663-46c0-aec0-c16c8e675e6a
  24. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    491ab715-f62a-46db-a56e-055cf7cb7bef
  25. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    eb9955ca-7e7b-40d3-a85d-58bb0d9ac897
  26. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5677b7e2-fa07-4536-96a9-2c64befd3751
  27. cpe:2.3:a:adobe:commerce_b2b:1.5.2:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    79cbdf59-eb84-44d3-81cf-5cbf943b411e
  28. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c175a1f-7814-4c51-a7b7-ad5140f0688f
  29. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2ade32d1-2845-4030-be1f-ece28189d0f9
  30. cpe:2.3:a:adobe:commerce_b2b:1.4.2:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    15c638a8-efe0-47db-b1f9-34093af0fc17
  31. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f2e771c9-86c4-455c-98d4-6f4fe7a9a822
  32. cpe:2.3:a:adobe:commerce_b2b:1.5.2:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2117b163-d88e-4eb4-aea7-f27fb732bd48
  33. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2dcd1522-6e27-474f-9fc6-413409d6ad55
  34. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f9258027-8a6a-4c6a-bc6f-349b6e03d828
  35. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    374e7edd-512a-4633-a136-01a656935334
  36. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    934c52c7-8751-481e-baa7-f631c4e31f32
  37. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    61559e50-581e-40ff-9fd4-10192ecfcd04
  38. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e66cbfb3-40c3-474a-a3a3-12135f610814
  39. cpe:2.3:a:adobe:commerce_b2b:1.4.2:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    500e3a54-d7c7-4887-9ea6-7df85389a831
  40. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de3bfb41-5633-4167-b1ea-9e958bce9dc2
  41. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6e94b136-7a2c-47f0-bce4-6bb8e776a305
  42. cpe:2.3:a:adobe:commerce_b2b:1.3.3:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b7968fca-ccfd-4222-8fb8-e6e21107944f
  43. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    89bab227-03e6-4776-ade4-9d9cb666efd9
  44. cpe:2.3:a:adobe:commerce_b2b:1.3.4:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e9d364a-c858-4160-8b8b-33ecf94796d9
NVD CPE · APPLICATIONadobemagentoVulnerable target · 46 assertions
Version 2.4.5; Version 2.4.6; Version 2.4.7; Version 2.4.8; Version 2.4.9Canonical identity product-93b17b2849c0a89f7601c92bffa8c491fbbc634bf8f11b99010d95c779e324dfLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:adobe:magento:2.4.8:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00e8284f-10cd-449c-aef1-688b8287292f
  2. cpe:2.3:a:adobe:magento:2.4.7:b2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fbcfe5fb-fab7-4bf0-90ae-79f9590fd872
  3. cpe:2.3:a:adobe:magento:2.4.7:p5:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d0c8648-b39e-47c7-aa5c-3afed22f8d40
  4. cpe:2.3:a:adobe:magento:2.4.7:beta3:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7eb4b9c5-513c-4039-8087-5e8880894318
  5. cpe:2.3:a:adobe:magento:2.4.6:p4:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a572a2dc-2dab-4abe-8fc2-5af2340c826f
  6. cpe:2.3:a:adobe:magento:2.4.7:b1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    99c620f3-40ed-4d7f-b6a1-205e948fd6f5
  7. cpe:2.3:a:adobe:magento:2.4.6:p6:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ba9cfc70-24cf-4dfa-aef9-9b5a9daf837d
  8. cpe:2.3:a:adobe:magento:2.4.5:p9:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5f2b6f1-ae8f-4aee-9ab3-080976ae48b7
  9. cpe:2.3:a:adobe:magento:2.4.6:p2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    02592d65-2d2c-460a-a970-8a18f9b156ed
  10. cpe:2.3:a:adobe:magento:2.4.7:p3:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8292888d-b0b0-4df3-8719-ea4cdcab39d1
  11. cpe:2.3:a:adobe:magento:2.4.6:p9:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a91e797d-63f6-4de8-869c-af0133dc6c03
  12. cpe:2.3:a:adobe:magento:2.4.6:p1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a3f113c0-00c5-4bc2-b42b-8ae3756252f2
  13. cpe:2.3:a:adobe:magento:2.4.5:p2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    510b1840-ae77-4bdd-9c09-26c64cc8fc81
  14. cpe:2.3:a:adobe:magento:2.4.7:p2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f5aac414-623c-444f-9bd5-ee0ace2b2246
  15. cpe:2.3:a:adobe:magento:2.4.8:beta1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59c10c74-fdb1-46ec-8f41-f3ac24aefb7d
  16. cpe:2.3:a:adobe:magento:2.4.5:p13:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e99c1f27-68c9-481f-b01d-8b58b0afb437
  17. cpe:2.3:a:adobe:magento:2.4.6:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    789bd987-9dad-4eae-93de-0e267d54f124
  18. cpe:2.3:a:adobe:magento:2.4.9:alpha1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e34849f7-54ee-4e4c-9184-3de9c30e12aa
  19. cpe:2.3:a:adobe:magento:2.4.5:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a41c717-4b9f-4972-aba3-2294eec20f3e
  20. cpe:2.3:a:adobe:magento:2.4.8:p2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f56f919-69b6-4a77-b8ce-f13409542f14
  21. cpe:2.3:a:adobe:magento:2.4.5:p7:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b9e8299d-fa97-483a-8e1b-ba7b869e467d
  22. cpe:2.3:a:adobe:magento:2.4.5:p5:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1c99b578-5dd6-476d-bb75-4dcad7f79535
  23. cpe:2.3:a:adobe:magento:2.4.7:p4:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9830e074-fdcf-41e9-98c7-10c20424ef4c
  24. cpe:2.3:a:adobe:magento:2.4.7:p6:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    082f8b60-ecc5-4c55-bbfe-a0c8a3e95590
  25. cpe:2.3:a:adobe:magento:2.4.5:p3:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa1edf58-8384-48c4-a584-54d24f6f7973
  26. cpe:2.3:a:adobe:magento:2.4.9:alpha2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4e21dff0-9f15-44d2-b78a-097bf3acd752
  27. cpe:2.3:a:adobe:magento:2.4.6:p3:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    457b89cf-c75e-4ed6-8603-9c52ba462a9e
  28. cpe:2.3:a:adobe:magento:2.4.7:p1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9c77154a-dbfe-48c3-a274-03075a0db040
  29. cpe:2.3:a:adobe:magento:2.4.6:p5:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2a2dd9c6-baf5-4df5-9c14-3478923b2019
  30. cpe:2.3:a:adobe:magento:2.4.6:p11:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ae724531-422d-4abb-98f5-2c0b1bbef031
  31. cpe:2.3:a:adobe:magento:2.4.5:p6:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c1b2897-79a5-4a5b-9137-7a4b6b85aa84
  32. cpe:2.3:a:adobe:magento:2.4.6:p10:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ae842cc8-7795-4238-b727-0ba2fffbf62c
  33. cpe:2.3:a:adobe:magento:2.4.6:p7:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2aa0b806-abb8-4c18-9f9c-8291be208f52
  34. cpe:2.3:a:adobe:magento:2.4.8:p1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    524f64b6-f7f7-4926-884f-e9448636007c
  35. cpe:2.3:a:adobe:magento:2.4.7:p7:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a7b83ad4-3134-414a-80e3-106c3c0f975a
  36. cpe:2.3:a:adobe:magento:2.4.5:p4:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d2d9715-3a6b-4be0-b1c5-8d19a683a083
  37. cpe:2.3:a:adobe:magento:2.4.5:p8:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9a1b92ec-e83a-43b3-8f14-5c1a52b579b1
  38. cpe:2.3:a:adobe:magento:2.4.6:p12:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb499397-0e40-45b0-a7e9-befcc909dd07
  39. cpe:2.3:a:adobe:magento:2.4.5:p11:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    08b7898f-e25a-4d16-a007-6d4543e80c58
  40. cpe:2.3:a:adobe:magento:2.4.5:p10:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    783e4af1-52f3-446b-b003-8079eda78cbf
  41. cpe:2.3:a:adobe:magento:2.4.6:p8:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa9d4dab-7567-48d7-be60-2a10b35cff27
  42. cpe:2.3:a:adobe:magento:2.4.5:p1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3fa80bbc-2df2-46e1-84ce-8a899415114e
  43. cpe:2.3:a:adobe:magento:2.4.5:p12:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    313cb0c1-2e8c-46ac-b72b-afa9e0a6e064
  44. cpe:2.3:a:adobe:magento:2.4.5:p14:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d4a3f4c7-8784-43bd-a11b-e66872dd8812
  45. cpe:2.3:a:adobe:magento:2.4.8:beta2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2957b390-52c5-48d7-a6d7-709bc76b9c69
  46. cpe:2.3:a:adobe:magento:2.4.7:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e06fe04-8844-4409-92d9-4972b47c921b

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.1
psirt@adobe.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
9.1
adobeCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.