Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Campaign CRITICAL 10.0
CVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitatio…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
C2pa HIGH 8.2
CVE-2026-48290

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the contex…

Fix: after 0.84.0
Fix from $1,950 2026-07-14
Coldfusion HIGH 7.7
CVE-2026-48332EPSS 11%

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacke…

Mitigation only
Fix from $1,950 2026-07-14
Experience Manager CRITICAL 9.6
CVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the conte…

Fix: after 2020.5.0
Fix from $2,300 2026-07-14
Coldfusion HIGH 8.6
CVE-2026-48285

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security fe…

Mitigation only
Fix from $1,950 2026-06-30
Campaign CRITICAL 10.0
CVE-2026-47938

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could resu…

Fix: after 7.4.2
Fix from $2,300 2026-06-09
Commerce HIGH 7.4
CVE-2026-34647

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (S…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Commerce MEDIUM 5.5
CVE-2026-21293

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Commerce MEDIUM 5.5
CVE-2026-21294

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Experience Manager MEDIUM 6.5
CVE-2025-54249

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Secu…

Fix: after 2025.8.0
Fix from $1,600 2025-09-09
Coldfusion MEDIUM 6.2
CVE-2025-49545

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitr…

Mitigation only
Fix from $1,600 2025-07-08
Commerce HIGH 7.7
CVE-2024-49521

Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature by…

Fix: 3.2.6+
Fix from $1,950 2024-11-12
Commerce HIGH 8.8
CVE-2024-34111

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could…

Fix: after 1.4.0
Fix from $1,950 2024-06-13
Commerce MEDIUM 6.8
CVE-2023-26366

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Server…

Mitigation only
Fix from $1,600 2023-10-13
Campaign MEDIUM 6.5
CVE-2022-42343

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead…

Fix: 7.3.2 / 8.4.2+
Fix from $1,600 2022-12-16
Adobe Commerce MEDIUM 6.6
CVE-2021-36043

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundl…

Fix: after 2.4.2
Fix from $1,600 2021-09-01
Experience Manager HIGH 8.8
CVE-2021-28627

Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticat…

Fix: after 6.5.8.0
Fix from $1,950 2021-08-24
Campaign Classic HIGH 8.6
CVE-2021-21009

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.…

Fix: after 20.3.1
Fix from $1,950 2021-01-13
Experience Manager Forms Add On MEDIUM 5.8
CVE-2020-24444

AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Req…

Mitigation only
Fix from $1,600 2020-12-10
Experience Manager HIGH 7.5
CVE-2020-9643

Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens…

Fix: 6.4.8.1 / 6.5.5.0+
Fix from $1,950 2020-06-12
Experience Manager HIGH 7.5
CVE-2020-9645

Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead t…

Fix: 6.4.8.1 / 6.5.5.0+
Fix from $1,950 2020-06-12
Experience Manager HIGH 7.5
CVE-2020-3769

Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sens…

Fix: after 6.5.0
Fix from $1,950 2020-03-25
Experience Manager HIGH 7.5
CVE-2018-12809

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive i…

Fix: after 6.4.0
Fix from $1,950 2018-07-20
Experience Manager HIGH 7.5
CVE-2018-5004

Adobe Experience Manager versions 6.2 and 6.3 have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive infor…

Fix: 6.4.0+
Fix from $1,950 2018-07-20
Experience Manager HIGH 7.5
CVE-2018-5006EPSS 54%

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive i…

Fix: after 6.4.0
Fix from $1,950 2018-07-20
Connect CRITICAL 10.0
CVE-2017-11291EPSS 6%

An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused t…

Fix: after 9.6.2
Fix from $2,300 2017-12-09