Executive brief
Adobe Commerce is an e-commerce platform used to build and operate online stores. A stored cross-site scripting vulnerability allows attackers with high-level administrative access to inject malicious scripts into form fields. When other users visit affected pages, the injected scripts execute in their browsers, enabling session hijacking and unauthorized access to customer accounts and order data.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Commerce form field handling. An attacker with high-level privileges can inject malicious JavaScript into vulnerable form fields, which persists in the application database. When legitimate users browse to pages containing the compromised fields, the payload executes in their browser context, allowing attackers to steal session tokens, modify account details, or perform actions on behalf of the victim. Exploitation requires user interaction (victim must view the affected page) and high-level attacker privileges.
Affected products
- Adobe Commerce 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, 2.4.9-alpha3 and earlier
Timeline
- 2026-03-11: disclosed