Description
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-07-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored Cross‑Site Scripting (XSS) flaw in Adobe Commerce allows a low‑privileged user to inject malicious JavaScript into form fields that are later displayed to other users. When a victim visits the affected page, the injected script runs in their browser with the site’s privileges, potentially enabling data theft, session hijacking, or further malicious actions. The vulnerability is classified as CWE‑79 and escalates the attacker’s privilege scope, making the impact more severe than a simple script injection.

Affected Systems

Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source are all susceptible to this flaw. The affected software does not have version information in the public advisory, so any deployment of these products prior to the latest patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% signifies a very low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. Attackers would need the ability to submit content to a vulnerable form, so the attack vector is likely local or requires user interaction. Even though exploitation likelihood is low, the potential for cross‑domain compromise makes it a notable risk for exposed sites.

Generated by OpenCVE AI on July 31, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Commerce to the latest patched version that contains the fix for the stored XSS flaw.
  • Verify that user‑supplied data is properly validated, sanitized, and encoded before rendering to prevent XSS execution.
  • Deploy a web application firewall or similar filtering rules to detect and block malicious XSS payloads in form submissions.

Generated by OpenCVE AI on July 31, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Adobe Commerce Webhooks Plugin Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T14:08:27.282Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48371

cve-icon Vulnrichment

Updated: 2026-07-15T14:08:23.548Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:53:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')