CVE-2026-48414 PUBLISHED

Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Assigner: adobe
Reserved: 21.05.2026 Published: 11.08.2026 Updated: 11.08.2026

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Scope is changed.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 7.7

Product Status

Vendor Adobe
Product Adobe Commerce
Versions Default: affected
  • affected from 0 to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug (incl.)
  • Version 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug is unaffected
Vendor Adobe
Product Adobe Commerce B2B
Versions Default: affected
  • affected from 0 to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul (incl.)
  • Version 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug is unaffected
Vendor Adobe
Product Magento Open Source
Versions Default: affected
  • affected from 0 to 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul (incl.)
  • Version 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug is unaffected

References

Problem Types

  • Cross-site Scripting (Stored XSS) (CWE-79) CWE