CVE-2025-47110

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field. Scope is changed to that of other high-privileged accounts, leading to a high impact on confidentiality, integrity, and availability.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
adobeCNA
8.4 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
adobecommerce
2.4.4
adobecommerce
2.4.4:p1
adobecommerce
2.4.4:p10
adobecommerce
2.4.4:p11
adobecommerce
2.4.4:p12
adobecommerce
2.4.4:p13
adobecommerce
2.4.4:p2
adobecommerce
2.4.4:p3
adobecommerce
2.4.4:p4
adobecommerce
2.4.4:p5
adobecommerce
2.4.4:p6
adobecommerce
2.4.4:p7
adobecommerce
2.4.4:p8
adobecommerce
2.4.4:p9
adobecommerce
2.4.5
adobecommerce
2.4.5:p1
adobecommerce
2.4.5:p10
adobecommerce
2.4.5:p11
adobecommerce
2.4.5:p12
adobecommerce
2.4.5:p2
adobecommerce
2.4.5:p3
adobecommerce
2.4.5:p4
adobecommerce
2.4.5:p5
adobecommerce
2.4.5:p6
adobecommerce
2.4.5:p7
adobecommerce
2.4.5:p8
adobecommerce
2.4.5:p9
adobecommerce
2.4.6
adobecommerce
2.4.6:p1
adobecommerce
2.4.6:p10
adobecommerce
2.4.6:p2
adobecommerce
2.4.6:p3
adobecommerce
2.4.6:p4
adobecommerce
2.4.6:p5
adobecommerce
2.4.6:p6
adobecommerce
2.4.6:p7
adobecommerce
2.4.6:p8
adobecommerce
2.4.6:p9
adobecommerce
2.4.7
adobecommerce
2.4.7:b1
adobecommerce
2.4.7:b2
adobecommerce
2.4.7:beta3
adobecommerce
2.4.7:p1
adobecommerce
2.4.7:p2
adobecommerce
2.4.7:p3
adobecommerce
2.4.7:p4
adobecommerce
2.4.7:p5
adobecommerce
2.4.8
adobecommerce_b2b
1.3.3
adobecommerce_b2b
1.3.3:p10
adobecommerce_b2b
1.3.3:p11
adobecommerce_b2b
1.3.3:p12
adobecommerce_b2b
1.3.3:p13
adobecommerce_b2b
1.3.4
adobecommerce_b2b
1.3.4:p10
adobecommerce_b2b
1.3.4:p11
adobecommerce_b2b
1.3.4:p12
adobecommerce_b2b
1.3.4:p9
adobecommerce_b2b
1.3.5
adobecommerce_b2b
1.3.5:p10
adobecommerce_b2b
1.3.5:p7
adobecommerce_b2b
1.3.5:p8
adobecommerce_b2b
1.3.5:p9
adobecommerce_b2b
1.4.2
adobecommerce_b2b
1.4.2:p1
adobecommerce_b2b
1.4.2:p2
adobecommerce_b2b
1.4.2:p3
adobecommerce_b2b
1.4.2:p4
adobecommerce_b2b
1.4.2:p5
adobecommerce_b2b
1.5.2
adobemagento
2.4.5
adobemagento
2.4.5:p1
adobemagento
2.4.5:p10
adobemagento
2.4.5:p11
adobemagento
2.4.5:p12
adobemagento
2.4.5:p2
adobemagento
2.4.5:p3
adobemagento
2.4.5:p4
adobemagento
2.4.5:p5
adobemagento
2.4.5:p6
adobemagento
2.4.5:p7
adobemagento
2.4.5:p8
adobemagento
2.4.5:p9
adobemagento
2.4.6
adobemagento
2.4.6:p1
adobemagento
2.4.6:p10
adobemagento
2.4.6:p2
adobemagento
2.4.6:p3
adobemagento
2.4.6:p4
adobemagento
2.4.6:p5
adobemagento
2.4.6:p6
adobemagento
2.4.6:p7
adobemagento
2.4.6:p8
adobemagento
2.4.6:p9
adobemagento
2.4.7
adobemagento
2.4.7:b1
adobemagento
2.4.7:b2
adobemagento
2.4.7:beta3
adobemagento
2.4.7:p1
adobemagento
2.4.7:p2
adobemagento
2.4.7:p3
adobemagento
2.4.7:p4
adobemagento
2.4.7:p5
adobemagento
2.4.8
𝑥
= Vulnerable software versions