| Security Announcement | Description | Affected Versions | Date |
| Configured Commerce Security Advisory - COM-2025-04 | User Enumeration | before 5.2.2605 | July 14, 2026 |
| Configured Commerce Security Advisory - COM-2025-03 | Password History Policy Bypass | before 5.2.2605 | July 14, 2026 |
| Configured Commerce Security Advisory - COM-2025-02 | Unverified Email Address Change | before 5.2.2605 | July 14, 2026 |
| Configured Commerce Security Advisory - COM-2025-01 | Broken Access Control | before 5.2.2606 (STS) and 5.2.2604 (LTS) | July 14, 2026 |
| Configured Commerce Security Advisory - COM-2024-06 | Session Token Submitted Using GET Method | before 5.2.2408 | Dec 13, 2024 |
| Configured Commerce Security Advisory - COM-2024-05 | Registration Mechanism Weakness | before 5.2.2408 | Dec 13, 2024 |
| Configured Commerce Security Advisory - COM-2024-04 | Insufficient Session Destruction | before 5.2.2408 | Dec 13, 2024 |
| Configured Commerce Security Advisory - COM-2024-03 | Improper Input Validation | before 5.2.2408 | Dec 13, 2024 |
| Configured Commerce Security Advisory - COM-2024-02 | Business Logic Flaws | before 5.2.2408 | Dec 13, 2024 |
| Configured Commerce Security Advisory - COM-2024-01 | Stored XSS vulnerability | before 5.2.2408 | Oct 4, 2024 |
Configured Commerce - Security Announcements
- Updated
Please sign in to leave a comment.