Executive brief
Adobe Commerce, a widely-used e-commerce platform, contains a stored cross-site scripting (XSS) vulnerability in form fields that allows attackers to inject malicious JavaScript code. When victims visit a page containing the injected code, the malicious script executes in their browser, potentially allowing an attacker to steal session tokens, compromise customer accounts, or take control of customer transactions and data.
Technical details
The vulnerability is a stored (persistent) cross-site scripting flaw in Adobe Commerce form handling that fails to properly sanitize user input before storing and displaying it. An attacker can inject malicious JavaScript into vulnerable form fields, which is then executed in the browser of any user who views the affected page. The attack requires no authentication and the scope is changed, meaning the vulnerability can impact other users or components. Attackers can gain elevated access, hijack sessions, or manipulate user actions without requiring user interaction beyond normal browsing.
Affected products
- Adobe Commerce
Timeline
- 2026-09-08: disclosed