Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe — Adobe Commerce
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Jun 13, 2024
- Modified
- Jun 17, 2026
- Added to KEV
- Jul 17, 2024
- Federal patch due
- Aug 7, 2024
CISA required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2024-34102, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- Chocapikk/CVE-2024-34102★ 48
CosmicSting (CVE-2024-34102)
updated Aug 10, 2026
- bigb0x/CVE-2024-34102★ 31
POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce.
updated Dec 20, 2025
- th3gokul/CVE-2024-34102★ 14
CVE-2024-34102: Unauthenticated Magento XXE
updated Aug 10, 2026
- jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento★ 9
CosmicSting: critical unauthenticated XXE vulnerability in Adobe Commerce and Magento (CVE-2024-34102)
updated Jan 17, 2026
- bughuntar/CVE-2024-34102★ 5
Exploitation CVE-2024-34102
updated Jun 21, 2026
- EQSTLab/CVE-2024-34102★ 5
Adobe Commerce XXE exploit
updated Aug 28, 2026
- 11whoami99/CVE-2024-34102★ 3
POC for CVE-2024-34102 : Unauthenticated Magento XXE and bypassing WAF , You will get http connection on ur webhook
updated Jan 1, 2026
- 0x0d3ad/CVE-2024-34102★ 2
CVE-2024-34102 (Magento XXE)
updated Nov 30, 2024
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2024-34102?
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
How severe is CVE-2024-34102?
CVE-2024-34102 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2024-34102 actively exploited in the wild?
Yes. CVE-2024-34102 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Jul 17, 2024, meaning CISA has confirmed evidence of active exploitation.
What is the EPSS score for CVE-2024-34102?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2024-34102?
Yes - a public Nuclei template referencing CVE-2024-34102 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2024-34102?
CVE-2024-34102 is classified under CWE-611 (Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)).
Cross-checked against
Impactr finds and proves whether CVE-2024-34102 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist