CVE-2026-21284 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: March 11, 2026
Adobe Commerce - Stored XSS
Overview
Adobe Commerce <= 2.4.9-alpha3 contains a stored XSS caused by insufficient sanitization in form fields, letting high-privileged attackers inject malicious scripts, exploit requires victim to browse vulnerable page.
Severity & Score
Impact
Attackers can execute malicious scripts in victim browsers, leading to session takeover and high confidentiality and integrity impact.
Mitigation
Update to the latest available version beyond 2.4.9-alpha3.
Social Media Activity(1 post)
š CVE-2026-21284 - High (8.1) Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts ... š https://www.thehackerwire.com/vulnerability/CVE-2026-21284/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-21284
- Severity
- High
- CVSS Score
- 8.1
- Type
- stored_xss
- Status
- confirmed
- EPSS
- 9.3%
- Social Posts
- 1
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N