Sap Commerce Cloud
21 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Sap Commerce Cloud, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Sap Commerce Cloud CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 1 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 2 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High4
- Medium12
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Sap Commerce Cloud.
- CVE-2026-44761Insecure Sample Credentials in SAP Commerce Cloud9.1
- CVE-2026-34263Missing authentication check in SAP Commerce cloud configuration9.6
- CVE-2026-24321Information Disclosure vulnerability in SAP Commerce Cloud5.3
- CVE-2026-23684Race condition vulnerability in SAP Commerce Cloud5.9
- CVE-2025-42906Directory Traversal vulnerability in SAP Commerce Cloud5.3
- CVE-2025-27435Information Disclosure Vulnerability in SAP Commerce Cloud4.2
- CVE-2025-26654Potential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud)6.8
- CVE-2024-47577Information Disclosure vulnerability in SAP Commerce Cloud2.7
- CVE-2024-41733Information Disclosure Vulnerability in SAP Commerce5.3
- CVE-2024-33003Information Disclosure Vulnerability in SAP Commerce Cloud7.4
- CVE-2023-42481Improper Access Control vulnerability in SAP Commerce Cloud8.1
- CVE-2023-37486Information Disclosure vulnerability in SAP Commerce (OCC API)5.9
- CVE-2021-33666When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware prolifer...6.1
- CVE-2021-21477SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject ma...9.9
- CVE-2021-21445SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation,...5.4
Product grouping is registry-driven, with AI assist and human review. How it works