SecBoard
Zurück zur CVE-Übersicht

CVE-2026-76200

CRITICAL(9.3)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Risk Signal Score23/100 — NIEDRIG
  • CVSS 9.3 — Kritisch

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.5%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.3

Technische Schwere

Beschreibung

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Betroffene Produkte

  • cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:-:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:b1:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:b2:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:beta3:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p1:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p10:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p2:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p3:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p4:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p5:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p6:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p7:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p8:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.7:p9:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.8:-:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.8:beta1:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.8:beta2:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.8:p1:*:*:open_source:*:*:*
  • cpe:2.3:a:adobe:magento:2.4.8:p2:*:*:open_source:*:*:*

Referenzen