Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.7
CVE-2026-48414PATCHED
adobe · adobe commerce

Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Description

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Scope is changed.

Affected Products

VendorProductVersions
adobeadobe commerce0, 0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobemagentocert_advisory90%

References

  • https://helpx.adobe.com/security/products/magento/apsb26-92.html(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories9h ago
[NEU] [hoch] Adobe Magento: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security10h ago
Patchday Adobe: Schadcode-Schlupflöcher bedrohen Campaign Classic und ColdFusion
→ No new info (linked only)
Tier C
VulDB23h ago
CVE-2026-48414 | Adobe Commerce/Commerce B2B/Magento Open Source Form Field cross site scripting
→ No new info (linked only)
CVSS 3.17.7 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug2.4.5-2026-aug2.4.4-2026-aug1.5.3-2026-aug1.5.2-2026-aug1.4.2-2026-aug1.3.4-2026-aug1.3.3-2026-aug2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug
CWECWE-79
PublishedAug 11, 2026
Trending Score46
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71362
Adobe Commerce | Incorrect Authorization (CWE-863)
Trending: 62
CRITICALCVE-2026-48362
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 62
HIGHCVE-2026-48386
ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
Trending: 47
HIGHCVE-2026-21279
ColdFusion | Improper Input Validation (CWE-20)
Trending: 47
HIGHCVE-2026-48441
Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Trending: 46

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 11, 2026