Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2022-24086

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

  • Published: Feb 16, 2022
  • Updated: May 4, 2025
  • CVE: CVE-2022-24086
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
magento / magento 2.4.0 2.4.2.x
adobe / commerce 2.3.7-p1 2.3.7-p1.x
adobe / commerce 2.4.3-p1 2.4.3-p1.x
adobe / commerce 2.4.3 2.4.3.x
adobe / commerce 2.4.0 2.4.2.x
adobe / commerce 2.3.7-p2 2.3.7-p2.x
magento / magento 2.4.3-p1 2.4.3-p1.x
magento / magento 2.4.3 2.4.3.x
magento / magento 2.3.7-p2 2.3.7-p2.x
magento / magento 2.3.7-p1 2.3.7-p1.x
adobe / commerce 2.3.3.x 2.3.6.x
magento / magento 2.3.3.x 2.3.6.x
magento / magento - 2.3.0
adobe / commerce - 2.3.0