Known vulnerabilities in Adobe Commerce (formerly Magento Commerce) 2.4.9-alpha3

Vendor: Adobe
Version: 2.4.9-alpha3
Software CPE: cpe:2.3:a:adobe:magento_commerce:*:*:*:*:*:*:*:*
Total vulnerabilities: 54
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Adobe Commerce (formerly Magento Commerce) version 2.4.9-alpha3 Adobe Commerce (formerly Magento Commerce) 2.4.9-alpha3 is affected by 54 vulnerabilities: 7 high, 14 medium, 33 low Critical High Medium Low

Vulnerabilities (54)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141504 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-48413
CWE-79 Low
No
No
2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug, 2.4.9-2026-aug 11.08.2026 SB2026081157
#VU141505 - Incorrect Authorization
CVE-2026-48415
CWE-863 Low
No
No
2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug, 2.4.9-2026-aug 11.08.2026 SB2026081157
#VU141506 - Incorrect Authorization
CVE-2026-48416
CWE-863 Medium
No
No
2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug, 2.4.9-2026-aug 11.08.2026 SB2026081157
#VU141507 - Incorrect Authorization
CVE-2026-48411
CWE-863 Low
No
No
2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug, 2.4.9-2026-aug 11.08.2026 SB2026081157
#VU141508 - Incorrect Authorization
CVE-2026-48412
CWE-863 Low
No
No
2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug, 2.4.9-2026-aug 11.08.2026 SB2026081157
#VU141502 - Incorrect Authorization
CVE-2026-71362
CWE-863 High
No
Exploited
2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug, 2.4.9-2026-aug 11.08.2026 SB2026081157
#VU141503 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-48414
CWE-79 Low
No
No
2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug, 2.4.9-2026-aug 11.08.2026 SB2026081157
#VU137585 - Unrestricted Upload of File with Dangerous Type
CVE-2026-48356
CWE-434 High
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137586 - Improper Encoding or Escaping of Output
CVE-2026-48358
CWE-116 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137587 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-47994
CWE-79 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137588 - Incorrect Authorization
CVE-2026-47988
CWE-863 High
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137589 - Incorrect Authorization
CVE-2026-47984
CWE-863 High
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137590 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-47995
CWE-79 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137591 - Incorrect Authorization
CVE-2026-47996
CWE-863 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137592 - Improper input validation
CVE-2026-47992
CWE-20 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137593 - Incorrect Authorization
CVE-2026-47997
CWE-863 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137594 - Incorrect Authorization
CVE-2026-47998
CWE-863 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137595 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-47999
CWE-79 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137596 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-48000
CWE-601 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509
#VU137597 - Exposure of sensitive information to an unauthorized actor
CVE-2026-48001
CWE-200 Low
No
No
2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul 15.07.2026 SB2026071509


Showing elements 1 - 20 out of 54