Medium severity4.8NVD Advisory· Published May 12, 2026· Updated May 13, 2026
CVE-2026-34655
CVE-2026-34655
Description
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected products
1- Range: <=2.4.9-beta1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
36- Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout SkimmingThe Hacker News · May 16, 2026
- Funnel Builder WordPress plugin bug exploited to steal credit cardsBleepingComputer · May 15, 2026
- Avada Builder WordPress plugin flaws allow site credential theftBleepingComputer · May 15, 2026
- White House cyber official: identity security matters more than ever in the age of AICyberScoop · May 14, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (May 4, 2026 to May 10, 2026)Wordfence Blog · May 14, 2026
- 18-year-old NGINX vulnerability allows DoS, potential RCEBleepingComputer · May 14, 2026
- Chipmaker Patch Tuesday: Intel and AMD Patch 70 VulnerabilitiesSecurityWeek · May 13, 2026
- Congressman launches inquiry into how food retailers use surveillance pricingThe Record · May 12, 2026
- Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-daysBleepingComputer · May 12, 2026
- Microsoft Patches 137 VulnerabilitiesSecurityWeek · May 12, 2026
- Škoda warns of customer data breach after online shop hackBleepingComputer · May 12, 2026
- Adobe Patches 52 Vulnerabilities in 10 ProductsSecurityWeek · May 12, 2026
- New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network PivotsThe Hacker News · May 12, 2026
- SAP Patches Critical S/4HANA, Commerce VulnerabilitiesSecurityWeek · May 12, 2026
- SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANABleepingComputer · May 12, 2026
- Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security · May 10, 2026
- Trellix source code breach claimed by RansomHouse hackersBleepingComputer · May 8, 2026
- Websites with an undefined trust level: avoiding the trapSecurelist · May 6, 2026
- The 2026 World Cup scam economy is already running before the first whistleMalwarebytes Labs · May 4, 2026
- Two cybersecurity pros get prison time for helping ransomware gangHelp Net Security · May 4, 2026
- Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701MThe Hacker News · May 4, 2026
- Cyber incident responders who carried out ransomware attacks given 4-year sentencesThe Record · May 1, 2026
- 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special CoverageDark Reading · May 1, 2026
- Two US Security Experts Sentenced to Prison for Helping Ransomware GangSecurityWeek · May 1, 2026
- US ransomware negotiators get 4 years in prison over BlackCat attacksBleepingComputer · May 1, 2026
- That AI Extension Helping You Write Emails? It’s Reading Them FirstUnit 42 · Apr 30, 2026
- The Good, the Bad and the Ugly in Cybersecurity – Week 17SentinelOne Labs · Apr 24, 2026
- UK Biobank Data Breach: Health Data of 500,000 Listed for Sale in ChinaInfosecurity Magazine · Apr 24, 2026
- Medical data of 500,000 UK volunteers listed for sale on AlibabaMalwarebytes Labs · Apr 24, 2026
- Former Ransomware Negotiator Pleads Guilty to Working For BlackCat Cyber GangInfosecurity Magazine · Apr 22, 2026
- Introducing the Agent Readiness score. Is your site agent-ready?Cloudflare Blog · Apr 17, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (March 23, 2026 to March 29, 2026)Wordfence Blog · Apr 2, 2026
- UK Cyber Monitoring Centre Sets Its Sights on US Expansion One Year After LaunchInfosecurity Magazine · Mar 17, 2026
- Researchers Warn of Global Surge in Fake Shipment Tracking ScamsInfosecurity Magazine · Mar 16, 2026
- Microsoft Patch Tuesday, March 2026 EditionKrebs on Security · Mar 11, 2026
- Is Poshmark safe? How to buy and sell without getting scammedESET WeLiveSecurity · Feb 19, 2026