Known Vulnerabilities for Commerce Server by Microsoft
Listed below are 9 of the newest known vulnerabilities associated with "Commerce Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-48013 json | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allow... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-48012 json | Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-34647 json | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server... | Not Provided | 2026-05-12 | 2026-08-27 |
| CVE-2026-21294 json | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Serve... | Not Provided | 2026-03-11 | 2026-08-27 |
| CVE-2026-21293 json | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Serve... | Not Provided | 2026-03-11 | 2026-08-27 |
| CVE-2026-14315 json | The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJ... | Not Provided | 2026-08-01 | 2026-08-12 |
| CVE-2012-1856 json | Not Provided | 2012-08-15 | 2026-04-22 | |
| CVE-2012-0158 json | Not Provided | 2012-04-10 | 2026-04-22 | |
| CVE-2007-1201 json | Not Provided | 2008-03-11 | 2026-04-23 | |
| CVE-2006-1257 json | Not Provided | 2006-03-19 | 2025-04-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Commerce Server | 2009 | |||
| Application | Microsoft | Commerce Server | 2009 | |||
| Application | Microsoft | Commerce Server | 2007 | |||
| Application | Microsoft | Commerce Server | 2002 | |||
| Application | Microsoft | Commerce Server | 2002 | |||
| Application | Microsoft | Commerce Server | 2002 | |||
| Application | Microsoft | Commerce Server | 2000 | |||
| Application | Microsoft | Commerce Server | 2000 | |||
| Application | Microsoft | Commerce Server | 2000 | |||
| Application | Microsoft | Commerce Server | - |