Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
7.7
CVE-2026-48414PATCHED
adobe · adobe commerce

Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Description

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Scope is changed.

Affected Products

VendorProductVersions
adobeadobe commerce0, 0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobemagentocert_advisory90%

References

  • https://helpx.adobe.com/security/products/magento/apsb26-92.html(vendor-advisory)

Related News (4 articles)

Tier D
BleepingComputer5m ago
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
→ No new info (linked only)
Tier B
BSI Advisories11h ago
[NEU] [hoch] Adobe Magento: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security12h ago
Patchday Adobe: Schadcode-Schlupflöcher bedrohen Campaign Classic und ColdFusion
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-48414 | Adobe Commerce/Commerce B2B/Magento Open Source Form Field cross site scripting
→ No new info (linked only)
CVSS 3.17.7 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug2.4.5-2026-aug2.4.4-2026-aug1.5.3-2026-aug1.5.2-2026-aug1.4.2-2026-aug1.3.4-2026-aug1.3.3-2026-aug2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug
CWECWE-79
PublishedAug 11, 2026
Trending Score51
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71362
Adobe Commerce | Incorrect Authorization (CWE-863)
Trending: 68
CRITICALCVE-2026-48362
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 62
HIGHCVE-2026-48413
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Trending: 48
HIGHCVE-2026-48386
ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
Trending: 46
HIGHCVE-2026-21279
ColdFusion | Improper Input Validation (CWE-20)
Trending: 46

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 11, 2026