Junglewise Threat Intelligence

CVE-2026-21284: Adobe Commerce stored XSS in form fields

CVE-2026-21284 · Severity: high · CVSS 8.1 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is an e-commerce platform used to build and operate online stores. A stored cross-site scripting vulnerability allows attackers with high-level administrative access to inject malicious scripts into form fields. When other users visit affected pages, the injected scripts execute in their browsers, enabling session hijacking and unauthorized access to customer accounts and order data.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Commerce form field handling. An attacker with high-level privileges can inject malicious JavaScript into vulnerable form fields, which persists in the application database. When legitimate users browse to pages containing the compromised fields, the payload executes in their browser context, allowing attackers to steal session tokens, modify account details, or perform actions on behalf of the victim. Exploitation requires user interaction (victim must view the affected page) and high-level attacker privileges.

Affected products

  • Adobe Commerce 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, 2.4.9-alpha3 and earlier

Timeline

  • 2026-03-11: disclosed

References

Related threats