Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
https://thehackernews.com/2025/03/over-1000-wordpress-sites-infected-with.html
https://www.theregister.com/2025/01/30/wacom_data_loss/
https://thehackernews.com/2024/10/alert-adobe-commerce-and-magento-stores.html
https://www.securityweek.com/recent-adobe-commerce-vulnerability-exploited-in-wild/
Published: 2024-06-13
Updated: 2024-11-29
Named Vulnerability: CosmicStingKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.94358