Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:*:*:*:*:*:*:*:* cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:* |
Wed, 11 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe commerce
Adobe commerce B2b Adobe magento |
|
| CPEs | cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p10:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p11:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p12:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p13:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p14:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p15:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p16:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.4:p9:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p10:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p11:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p12:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p13:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p14:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p15:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.5:p9:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p10:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p11:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p12:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p13:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.6:p9:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:b1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:b2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:beta3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.7:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.8:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.8:beta1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.8:beta2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.8:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.8:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.8:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.9:alpha1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.9:alpha2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce:2.4.9:alpha3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p10:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p11:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p12:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p13:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p14:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p15:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p16:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.3:p9:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p10:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p11:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p12:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p13:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p14:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p15:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.4:p9:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p10:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p11:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p12:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p13:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.3.5:p9:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p4:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p5:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p6:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p7:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.4.2:p8:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.5.2:-:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.5.2:p1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.5.2:p2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.5.2:p3:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.5.3:alpha1:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.5.3:alpha2:*:*:*:*:*:* cpe:2.3:a:adobe:commerce_b2b:1.5.3:alpha3:*:*:*:*:*:* cpe:2.3:a:adobe:magento:2.4.5:-:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p10:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p11:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p12:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p13:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p14:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p15:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p1:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p2:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p3:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p4:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p5:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p6:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p7:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p8:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.5:p9:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:-:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p10:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p11:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p12:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p13:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p1:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p2:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p3:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p4:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p5:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p6:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p7:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p8:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.6:p9:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:-:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:b1:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:b2:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:beta3:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p1:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p2:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p3:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p4:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p5:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p6:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p7:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.7:p8:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.8:-:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.8:beta1:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.8:beta2:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.8:p1:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.8:p2:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.8:p3:*:*:open_source:*:*:* cpe:2.3:a:adobe:magento:2.4.9:alpha3:*:*:open_source:*:*:* |
|
| Vendors & Products |
Adobe commerce
Adobe commerce B2b Adobe magento |
Wed, 11 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe adobe Commerce |
|
| Vendors & Products |
Adobe
Adobe adobe Commerce |
Wed, 11 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field. | |
| Title | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2026-03-11T02:19:20.459Z
Updated: 2026-03-12T03:55:22.193Z
Reserved: 2025-12-12T22:01:18.189Z
Link: CVE-2026-21284
Updated: 2026-03-11T13:35:56.225Z
Status : Analyzed
Published: 2026-03-11T03:15:53.040
Modified: 2026-03-11T18:22:00.580
Link: CVE-2026-21284
No data.