CVE Tools

Commerce

263 CVEs tracked. 5 of them are in CISA KEV.

This hub aggregates every CVE we track for Commerce, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Commerce CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Commerce CVEs per month
MonthCVEs
2024-1022
2024-111
2024-120
2025-010
2025-0223
2025-030
2025-044
2025-050
2025-066
2025-070
2025-086
2025-091
2025-105
2025-110
2025-120
2026-010
2026-0210
2026-0326
2026-043
2026-0515
2026-060
2026-0715
2026-087
2026-0910

Severity

How the 263 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2510%
  • High9236%
  • Medium12448%
  • Low187%

Latest CVEs

The 15 most recently published vulnerabilities affecting Commerce.

  1. CVE-2026-55795Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass—
  2. CVE-2026-76200Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)9.3
  3. CVE-2026-76201Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)9.3
  4. CVE-2026-77109Adobe Commerce | Incorrect Authorization (CWE-863)8.6
  5. CVE-2026-77110Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)7.6
  6. CVE-2026-77108Adobe Commerce | Incorrect Authorization (CWE-863)7.5
  7. CVE-2026-76202Adobe Commerce | Incorrect Authorization (CWE-863)8.2
  8. CVE-2026-77774Adobe Commerce | Incorrect Authorization (CWE-863)8.6
  9. CVE-2026-77111Adobe Commerce | Incorrect Authorization (CWE-863)8.7
  10. CVE-2026-75650Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)10.0
  11. CVE-2026-48416Adobe Commerce | Incorrect Authorization (CWE-863)7.5
  12. CVE-2026-48414Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)7.7
  13. CVE-2026-48413Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)8.7
  14. CVE-2026-48415Adobe Commerce | Incorrect Authorization (CWE-863)7.6
  15. CVE-2026-48412Adobe Commerce | Incorrect Authorization (CWE-863)2.7

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store