Commerce Webhooks
Vendor:
First CVE: Jun 13, 2024 · Active for 2 years
10
Total CVEs
More Total CVEs than 88% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 61% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Commerce Webhooks over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 13, 2024
2 years ago
Most Recent CVE
Jun 13, 2024
771 days ago
CVE Severity & Scoring
Commerce Webhooks10 CVEs
20%
60%
20%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High4 (40.0%)
None5 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-34102CRITICAL Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could re | Jun 13, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-34107CRITICAL Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An | Jun 13, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-34104HIGH Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An a | Jun 13, 2024 | 8.2 | 23 | NO | NO |
CVE-2024-34111HIGH Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system | Jun 13, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-34103HIGH Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attac | Jun 13, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-34108HIGH Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in | Jun 13, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-34110HIGH Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitr | Jun 13, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-34109HIGH Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in | Jun 13, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-34106MEDIUM Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An | Jun 13, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-34105MEDIUM Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker | Jun 13, 2024 | 4.8 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
1 CVE
10.0% of CVEs· 97th percentile
Metasploit
1 CVE
10.0% of CVEs· 97th percentile
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Commerce Webhooks
Top CWEs
Versions
No cataloged versions.