Configured Commerce
Vendor:
First CVE: Dec 18, 2024 · Active for 1 year
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Configured Commerce over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2024
19 months ago
Most Recent CVE
Jan 4, 2025
566 days ago
CVE Severity & Scoring
Configured Commerce8 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None4 (50.0%)
Unknown0 (0.0%)
Required4 (50.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-56174HIGH In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side tem | Dec 18, 2024 | 8.1 | 23 | NO | NO |
CVE-2025-22387HIGH An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL pa | Jan 4, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-22386HIGH An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active | Jan 4, 2025 | 7.3 | 21 | NO | NO |
CVE-2025-22384HIGH An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows st | Jan 4, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-22385MEDIUM An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium | Jan 4, 2025 | 5.9 | 18 | NO | NO |
CVE-2024-56175MEDIUM In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side tem | Dec 18, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-22383MEDIUM An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us | Jan 4, 2025 | 4.6 | 16 | NO | NO |
CVE-2024-56173MEDIUM In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in a | Dec 18, 2024 | 4.7 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Configured Commerce
Top CWEs
Versions
No cataloged versions.