Vulnerability Database

With exploit

airvae / commerce

Title Severity Exploit Date Affected Version
CVE-2008-5223 High Nov 25, 2008 == 3.0

commerceguys / commerce

Title Severity Exploit Date Affected Version
CVE-2014-9025 Medium Nov 20, 2014 == 7.x-1.1
== 7.x-1.0-rc3
== 7.x-1.0-alpha3
== 7.x-1.0-beta1
== 7.x-1.0-alpha4
== 7.x-1.0-alpha1
== 7.x-1.0
== 7.x-1.0-alpha5
== 7.x-1.0-beta4
== 7.x-1.0-alpha2
== 7.x-1.0-rc2
== 7.x-1.0-beta3
== 7.x-1.0-rc1
== 7.x-1.0-beta2
CVE-2012-1639 Low Oct 1, 2012 <= 7.x-1.1
== 7.x-1.0-beta3
== 7.x-1.0-alpha3
== 7.x-1.0-rc2
== 7.x-1.0-alpha5
== 7.x-1.0-beta2
== 7.x-1.0-alpha2
== 7.x-1.0-beta1
== 7.x-1.0
== 7.x-1.0-alpha1
== 7.x-1.0-alpha4
== 7.x-1.0-beta4
== 7.x-1.0-rc1
== 7.x-1.x-dev

oracle / commerce

Title Severity Exploit Date Affected Version
CVE-2017-3572 High Apr 24, 2017 == 6.2.2
== 6.3.0
== 6.4.1.2
== 6.5.0
== 6.5.1
== 6.5.2

sap / commerce

Title Severity Exploit Date Affected Version
CVE-2024-41733 Medium Aug 13, 2024 == com_cloud_2211
== hy_com_2205
CVE-2022-41204 High Oct 11, 2022 == 1905
== 2005
== 2011
== 2105
== 2205
CVE-2021-42064 Critical Dec 14, 2021 == 1905
== 2005
== 2011
== 2105
CVE-2021-40502 High Nov 10, 2021 == 2105.3
== 2011.13
== 2005.18
== 1905.34
CVE-2021-27619 Medium May 11, 2021 == 1808
== 1811
== 1905
== 2005
== 2011
CVE-2021-27602 Critical Apr 13, 2021 == 1808
== 1811
== 1905
== 2005
== 2011
CVE-2021-21477 Critical Feb 9, 2021 == 1808
== 1811
== 1905
== 2005
== 2011
CVE-2020-6302 High Sep 9, 2020 == 6.7
== 1808
== 1811
== 1905
== 2005
CVE-2020-6264 High Jun 10, 2020 == 6.7
== 1808
== 1811
== 1905
CVE-2020-6265 Critical Jun 9, 2020 == 6.7
== 1808
== 1811
== 1905

mangboard / commerce

Title Severity Exploit Date Affected Version
CVE-2021-26631 High May 19, 2022 < 1.3.9

adobe / commerce

Title Severity Exploit Date Affected Version
CVE-2025-47110 Critical Jun 10, 2025 == 2.4.4
== 2.4.4-p1
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.4-p13
== 2.4.4-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5
== 2.4.5-p1
== 2.4.5-p10
== 2.4.5-p11
== 2.4.5-p12
== 2.4.5-p2
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6
== 2.4.6-p1
== 2.4.6-p10
== 2.4.6-p2
== 2.4.6-p3
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.6-p9
== 2.4.7
== 2.4.7-b1
== 2.4.7-b2
== 2.4.7-beta3
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.7-p4
== 2.4.7-p5
== 2.4.8
CVE-2025-43586 High Jun 10, 2025 == 2.4.4
== 2.4.4-p1
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.4-p13
== 2.4.4-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5
== 2.4.5-p1
== 2.4.5-p10
== 2.4.5-p11
== 2.4.5-p12
== 2.4.5-p2
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6
== 2.4.6-p1
== 2.4.6-p10
== 2.4.6-p2
== 2.4.6-p3
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.6-p9
== 2.4.7
== 2.4.7-b1
== 2.4.7-b2
== 2.4.7-beta3
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.7-p4
== 2.4.7-p5
== 2.4.8
CVE-2025-43585 High Jun 10, 2025 == 2.4.4
== 2.4.4-p1
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.4-p13
== 2.4.4-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5
== 2.4.5-p1
== 2.4.5-p10
== 2.4.5-p11
== 2.4.5-p12
== 2.4.5-p2
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6
== 2.4.6-p1
== 2.4.6-p10
== 2.4.6-p2
== 2.4.6-p3
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.6-p9
== 2.4.7
== 2.4.7-b1
== 2.4.7-b2
== 2.4.7-beta3
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.7-p4
== 2.4.7-p5
== 2.4.8
CVE-2025-27206 Medium Jun 10, 2025 == 2.4.4
== 2.4.4-p1
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.4-p13
== 2.4.4-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5
== 2.4.5-p1
== 2.4.5-p10
== 2.4.5-p11
== 2.4.5-p12
== 2.4.5-p2
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6
== 2.4.6-p1
== 2.4.6-p10
== 2.4.6-p2
== 2.4.6-p3
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.6-p9
== 2.4.7
== 2.4.7-b1
== 2.4.7-b2
== 2.4.7-beta3
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.7-p4
== 2.4.7-p5
== 2.4.8
CVE-2025-27192 Low Apr 8, 2025 == 2.4.4
== 2.4.5
== 2.4.4-p1
< 2.4.4
== 2.4.5-p1
== 2.4.4-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.5-p2
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.6
== 2.4.6-p1
== 2.4.6-p2
== 2.4.6-p3
== 2.4.7-b1
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.4-p6
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5-p10
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.7
== 2.4.7-b2
== 2.4.7-beta3
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.5-p11
== 2.4.6-p9
== 2.4.7-p4
== 2.4.8-beta2
CVE-2025-27191 Medium Apr 8, 2025 == 2.4.4
== 2.4.5
== 2.4.4-p1
< 2.4.4
== 2.4.5-p1
== 2.4.4-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.5-p2
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.6
== 2.4.6-p1
== 2.4.6-p2
== 2.4.6-p3
== 2.4.7-b1
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.4-p6
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5-p10
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.7
== 2.4.7-b2
== 2.4.7-beta3
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.5-p11
== 2.4.6-p9
== 2.4.7-p4
== 2.4.8-beta2
CVE-2025-27190 Medium Apr 8, 2025 == 2.4.4
== 2.4.5
== 2.4.4-p1
== 2.4.5-p1
== 2.4.4-p2
== 2.4.5-p2
== 2.4.7-b1
== 2.4.6
== 2.4.6-p1
== 2.4.6-p2
== 2.4.6-p3
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.7
== 2.4.7-b2
== 2.4.7-beta3
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.6-p9
== 2.4.5-p10
== 2.4.5-p11
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.8-beta2
== 2.4.7-p4
CVE-2025-27188 Medium Apr 8, 2025 == 2.4.4
== 2.4.5
== 2.4.4-p1
< 2.4.4
== 2.4.5-p1
== 2.4.4-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.5-p2
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.6
== 2.4.6-p1
== 2.4.6-p2
== 2.4.6-p3
== 2.4.4-p7
== 2.4.4-p8
== 2.4.4-p9
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p12
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.5-p10
== 2.4.5-p11
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.6-p9
== 2.4.7
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.7-p4
== 2.4.8-beta2
CVE-2025-24434 Critical Feb 11, 2025 == 2.4.4
== 2.4.5
== 2.4.4-p1
== 2.4.5-p1
== 2.4.4-p2
== 2.4.5-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.4-p7
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.6
== 2.4.6-p1
== 2.4.6-p2
== 2.4.6-p3
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5-p10
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.7
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.8-beta1
CVE-2025-24425 Medium Feb 11, 2025 == 2.4.4
== 2.4.5
== 2.4.4-p1
< 2.4.4
== 2.4.5-p1
== 2.4.4-p2
== 2.4.5-p2
== 2.4.4-p3
== 2.4.4-p4
== 2.4.4-p5
== 2.4.4-p6
== 2.4.5-p3
== 2.4.5-p4
== 2.4.5-p5
== 2.4.6
== 2.4.6-p1
== 2.4.6-p2
== 2.4.6-p3
== 2.4.4-p7
== 2.4.4-p10
== 2.4.4-p11
== 2.4.4-p8
== 2.4.4-p9
== 2.4.5-p10
== 2.4.5-p6
== 2.4.5-p7
== 2.4.5-p8
== 2.4.5-p9
== 2.4.6-p4
== 2.4.6-p5
== 2.4.6-p6
== 2.4.6-p7
== 2.4.6-p8
== 2.4.7
== 2.4.7-p1
== 2.4.7-p2
== 2.4.7-p3
== 2.4.8-beta1

oro / commerce

Title Severity Exploit Date Affected Version
CVE-2023-32065 Medium Nov 28, 2023 >= 4.2.0 <= 4.2.10
>= 5.0.0 < 5.0.11
>= 5.1.0 < 5.1.1
CVE-2022-35950 Low Oct 9, 2023 >= 4.1.0 <= 4.1.13
>= 4.2.0 <= 4.2.10
>= 5.0.0 < 5.0.11
>= 5.1.0 < 5.1.1
CVE-2022-31037 Medium Oct 18, 2022 >= 4.1.0 < 5.0.6
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor Medium Jul 15, 2022 >= 5.0 < 5.0.4

ibexa / commerce

Title Severity Exploit Date Affected Version
CVE-2022-48366 Low Mar 12, 2023 >= 4.1.0 < 4.1.4
>= 4.0.0 < 4.0.7
>= 3.3.0 < 3.3.18
>= 2.5.0 < 2.5.13

hcltech / commerce

Title Severity Exploit Date Affected Version
CVE-2023-37532 Low Oct 23, 2023 >= 9.1.8 <= 9.1.13.2