cbcvebase.
CVE-2025-54236
published 2025-09-09

CVE-2025-54236: Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
KEVEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-11-14
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

Affected

23 ranges
VendorProductVersion rangeFixed in
adobeadobe_commerce<= 2.4.4-p15
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobemagento
adobemagento
adobemagento
adobemagento
adobemagento
magentocommunity-edition0 – 2.4.5-p14
magentocommunity-edition2.4.6-p1 – 2.4.6-p12
magentocommunity-edition2.4.7-beta1 – 2.4.7-p7
magentocommunity-edition2.4.8-beta1 – 2.4.8-p2
magentocommunity-edition2.4.9-alpha1 – 2.4.9-alpha2
magentoproject-community-edition0 – 2.0.2

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vulncheck9.1CRITICAL
cisa9.1CRITICAL