All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-48413
HIGHpublished 2026-08-11 18:17 UTC · 1 day ago · modified 2026-08-12 21:03 UTC
8.7
CVSS / 10
// description
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
// weaknesses (CWE)
- CWE-79