Executive brief
Adobe Commerce is an e-commerce platform used by thousands of online retailers to manage product catalogs, orders, and customer interactions. A stored cross-site scripting (XSS) vulnerability allows attackers with low-level administrative access to inject malicious scripts into form fields, which execute when other administrators or users view those pages. This could lead to credential theft, session hijacking, or unauthorized administrative actions.
Technical details
A stored cross-site scripting vulnerability exists in Adobe Commerce form field handling, affecting versions 2.4.4-p16 and earlier through 2.4.9-alpha3. The vulnerability is triggered when a low-privileged attacker injects malicious JavaScript into vulnerable form fields; the script is persistently stored and executed in the browsers of subsequent users who view the affected page. Exploitation requires user interaction—specifically, a victim must navigate to the page containing the injected payload. Patches are available for affected versions.
Affected products
- Adobe Commerce 2.4.4-p16 and earlier, 2.4.5-p15 and earlier, 2.4.6-p13 and earlier, 2.4.7-p8 and earlier, 2.4.8-p3 and earlier, 2.4.9-alpha3 and earlier
Timeline
- 2026-03-11: disclosed