CyberSec.Space Logo
Back to CVE Browser

CVE-2025-54236

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
9.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-09-09
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

Affected Platforms (CPE)

πŸ“¦
Adobe

Commerce

= 2.4.4= 2.4.5= 2.4.6= 2.4.7= 2.4.8= 2.4.9
πŸ“¦
Adobe

Commerce B2b

= 1.3.3= 1.3.4= 1.4.2= 1.5.2= 1.5.3
πŸ“¦
Adobe

Magento

= 2.4.5= 2.4.6= 2.4.7= 2.4.8= 2.4.9

References & Advisories

Related Security Intelligence Articles

Related Vulnerabilities