Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-34102
https://helpx.adobe.com/security/products/magento/apsb24-40.html
https://thehackernews.com/2025/10/over-250-magento-stores-hit-overnight.html
https://thehackernews.com/2025/03/over-1000-wordpress-sites-infected-with.html
https://www.theregister.com/2025/01/30/wacom_data_loss/
https://thehackernews.com/2024/10/alert-adobe-commerce-and-magento-stores.html
https://www.securityweek.com/recent-adobe-commerce-vulnerability-exploited-in-wild/
https://github.com/spacewasp/public_docs/blob/main/CVE-2024-34102.md
https://github.com/russellwork2021-lgtm/cosmicsting-cve-2024-34102-exploit
https://github.com/nmmorette/CVE-2024-34102
https://github.com/wubinworks/magento2-session-reaper-patch
https://github.com/Kento-Sec/CVE-2024-34102
https://github.com/th3gokul/CVE-2024-50603
https://github.com/wubinworks/magento2-encryption-key-manager-cli
https://github.com/wubinworks/magento2-template-filter-patch
https://github.com/bka/magento-cve-2024-34102-exploit-cosmicstring
https://github.com/dream434/CVE-2024-34102
https://github.com/Jhonsonwannaa/CVE-2024-34102
https://github.com/WTN-arny/CVE-2024-37085
https://github.com/WTN-arny/Vmware-ESXI
https://github.com/wubinworks/magento2-cosmic-sting-patch
https://github.com/etx-Arn/CVE-2024-34102-RCE-PoC
https://github.com/etx-Arn/CVE-2024-34102-RCE
https://github.com/Phantom-IN/CVE-2024-34102
https://github.com/bughuntar/CVE-2024-34102-Python
https://github.com/bughuntar/CVE-2024-34102
https://github.com/crynomore/CVE-2024-34102
https://github.com/RevoltSecurities/CVE-2024-36401
https://github.com/jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento
https://github.com/cmsec423/CVE-2024-34102
https://github.com/Chocapikk/CVE-2024-34102
https://github.com/th3gokul/CVE-2024-34102
Published: 2024-06-13
Updated: 2025-10-23
Named Vulnerability: CosmicStingKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99994