CVE Tools

Commerce Cloud

18 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Commerce Cloud, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Commerce Cloud CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Commerce Cloud CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-022
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical211%
  • High528%
  • Medium1161%

Latest CVEs

The 15 most recently published vulnerabilities affecting Commerce Cloud.

  1. CVE-2026-24321Information Disclosure vulnerability in SAP Commerce Cloud5.3
  2. CVE-2026-23684Race condition vulnerability in SAP Commerce Cloud5.9
  3. CVE-2024-33003Information Disclosure Vulnerability in SAP Commerce Cloud7.4
  4. CVE-2023-42481Improper Access Control vulnerability in SAP Commerce Cloud8.1
  5. CVE-2023-37486Information Disclosure vulnerability in SAP Commerce (OCC API)5.9
  6. CVE-2023-39439SAP Commerce accepts empty passphrases.8.8
  7. CVE-2021-33666When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware prolifer...6.1
  8. CVE-2021-21445SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation,...5.4
  9. CVE-2020-26809SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders...5.3
  10. CVE-2020-6363SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with user...4.6
  11. CVE-2020-6272SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several ...5.4
  12. CVE-2020-6238SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and...9.3
  13. CVE-2020-6232SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.5.3
  14. CVE-2020-6201The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP re...6.1
  15. CVE-2020-6200The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templati...5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store