Known Vulnerabilities for Commerce Platform by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Commerce Platform" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40887 json | Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40488 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-40098 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-39851 json | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mu... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-35407 json | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and author... | Not Provided | 2026-04-08 | 2026-04-10 |
| CVE-2026-35401 json | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can includ... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-33756 json | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batchi... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-32272 json | Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists... | Not Provided | 2026-04-13 | 2026-04-14 |
| CVE-2026-32271 json | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an ... | Not Provided | 2026-04-13 | 2026-04-16 |
| CVE-2026-32270 json | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the Payments... | Not Provided | 2026-04-13 | 2026-04-14 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Commerce Platform | 9.4 | |||
| Application | Oracle | Commerce Platform | 3.1.2 | |||
| Application | Oracle | Commerce Platform | 3.1.1 | |||
| Application | Oracle | Commerce Platform | 3.0.2 | |||
| Application | Oracle | Commerce Platform | 11.3.1 | |||
| Application | Oracle | Commerce Platform | 11.2.0.3 | |||
| Application | Oracle | Commerce Platform | 11.2.0.2 | |||
| Application | Oracle | Commerce Platform | 11.1 | |||
| Application | Oracle | Commerce Platform | 11.0 | |||
| Application | Oracle | Commerce Platform | 10.2.0.5 | |||
| Application | Oracle | Commerce Platform | 10.2 | |||
| Application | Oracle | Commerce Platform | 10.0.3.5 | |||
| Application | Oracle | Commerce Platform | 10.0 |