← Back to CVE List
Vulnerability Intelligence Report
Adobe Commerce Stored XSS Arbitrary code execution

CVE-2022-35698

Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:9.72%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-79 ↗Cross-site Scripting (Stored XSS) (CWE-79)

Affected Products & Versions

Vendor Product Affected Versions
Adobe Magento Commerce unspecified <= 2.4.5 (affected), unspecified <= 2.4.4-p1 (affected), unspecified <= None (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
9.722%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2022-07-12T00:00:00
Published2022-10-14T19:48:10
Patch Date2022-10-11
Last Updated2025-04-23T16:47:15

LINK COPIED TO CLIPBOARD