HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-48413 — Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability ...

·Source: NIST NVD

Updated:

Executive Summary

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope i

Analysis

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. CVSS Score: 8.7. Published: 2026-08-11T18:17:31.150.

Indicators of Compromise (1)

CVE (1)
CVE-2026-48413
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats