High - CVE-2024-39401 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High - CVE-2024-39402 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
High - CVE-2024-39403 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to...
Medium - CVE-2024-39404 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged...
Medium - CVE-2024-39405 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged...
Medium - CVE-2024-39406 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability...
Medium - CVE-2024-39407 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged...
Medium - CVE-2024-39408 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features...
Medium - CVE-2024-39409 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features...
NA - CVE-2024-39410 - Adobe Commerce versions 2.4.7-p1, 2.4.6-p6,...
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features...