Known Vulnerabilities for Commerce Server by Microsoft
Listed below are 9 of the newest known vulnerabilities associated with "Commerce Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40488 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-32271 json | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an ... | Not Provided | 2026-04-13 | 2026-04-16 |
| CVE-2026-25525 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-0926 json | The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 v... | Not Provided | 2026-02-19 | 2026-04-08 |
| CVE-2023-6120 json | The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 ... | Not Provided | 2023-12-09 | 2026-04-08 |
| CVE-2021-4375 json | The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the us... | Not Provided | 2023-06-07 | 2026-04-08 |
| CVE-2012-1856 json | Not Provided | 2012-08-15 | 2026-04-22 | |
| CVE-2012-0158 json | Not Provided | 2012-04-10 | 2026-04-22 | |
| CVE-2007-1201 json | Not Provided | 2008-03-11 | 2026-04-23 | |
| CVE-2006-1257 json | Not Provided | 2006-03-19 | 2025-04-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Commerce Server | 2009 | |||
| Application | Microsoft | Commerce Server | 2009 | |||
| Application | Microsoft | Commerce Server | 2007 | |||
| Application | Microsoft | Commerce Server | 2002 | |||
| Application | Microsoft | Commerce Server | 2002 | |||
| Application | Microsoft | Commerce Server | 2002 | |||
| Application | Microsoft | Commerce Server | 2000 | |||
| Application | Microsoft | Commerce Server | 2000 | |||
| Application | Microsoft | Commerce Server | 2000 | |||
| Application | Microsoft | Commerce Server | - |