Junglewise Threat Intelligence

CVE-2026-48371: Adobe Commerce stored XSS in form fields

CVE-2026-48371 · Severity: medium · CVSS 5.4 · Published 2026-07-14

Executive brief

Adobe Commerce and Magento Open Source are e-commerce platforms used to build and manage online stores. A security vulnerability has been identified where a low-privileged user, such as a store contributor, can inject malicious scripts into form fields. If an administrator or another user views the affected page, these scripts could execute in their browser, potentially leading to unauthorized actions or data theft.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Commerce, Magento Open Source, and related plugins due to improper neutralization of input during web page generation. An attacker with low-level privileges can inject malicious JavaScript into vulnerable form fields. The exploit is triggered when a victim (typically an administrator) navigates to the page where the malicious script has been stored, causing the script to execute within the context of the victim's browser session. This vulnerability has a CVSS score of 5.4, reflecting that while it requires user interaction and authentication, the scope is changed. Patches have been released in the July 2026 security updates.

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats