Junglewise Threat Intelligence

CVE-2026-47999: Adobe Commerce stored XSS in form fields

CVE-2026-47999 · Severity: medium · CVSS 4.8 · Published 2026-07-14

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Magento Open Source, Adobe Commerce B2b, Adobe Commerce Webhooks Plugin. Vendors: Adobe.

Executive brief

Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security vulnerability that allows high-privileged users to inject malicious scripts into form fields. If a victim views a page containing this malicious script, it could execute in their browser, potentially leading to unauthorized actions or data exposure. This risk is primarily internal, as it requires an attacker to already have significant administrative access to the platform.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Commerce, Magento Open Source, and related components. The flaw is located in vulnerable form fields that do not properly neutralize input before it is rendered in the web page. An attacker with high-privileged administrative access can inject malicious JavaScript that executes in the context of another user's browser session when they visit the affected page. The vulnerability has a CVSS score of 4.8, reflecting that while the impact involves a scope change, it requires high privileges and user interaction. Adobe has released patches to address this issue across multiple versions.

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats