CVE-2025-54236

CRITICAL9.1⚠ KEVEPSS 72.2%

Magento Community Edition Improper Input Validation vulnerability

Published: 9/9/2025Modified: 10/27/2025Added to CISA KEV: 10/24/2025
Also known as:GHSA-wh92-6q6g-px7j

Description

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References (6)