CVE-2025-54236

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
adobeCNA
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
adobecommerce
2.4.4
adobecommerce
2.4.4:p1
adobecommerce
2.4.4:p10
adobecommerce
2.4.4:p11
adobecommerce
2.4.4:p12
adobecommerce
2.4.4:p13
adobecommerce
2.4.4:p14
adobecommerce
2.4.4:p15
adobecommerce
2.4.4:p2
adobecommerce
2.4.4:p3
adobecommerce
2.4.4:p4
adobecommerce
2.4.4:p5
adobecommerce
2.4.4:p6
adobecommerce
2.4.4:p7
adobecommerce
2.4.4:p8
adobecommerce
2.4.4:p9
adobecommerce
2.4.5
adobecommerce
2.4.5:p1
adobecommerce
2.4.5:p10
adobecommerce
2.4.5:p11
adobecommerce
2.4.5:p12
adobecommerce
2.4.5:p13
adobecommerce
2.4.5:p14
adobecommerce
2.4.5:p2
adobecommerce
2.4.5:p3
adobecommerce
2.4.5:p4
adobecommerce
2.4.5:p5
adobecommerce
2.4.5:p6
adobecommerce
2.4.5:p7
adobecommerce
2.4.5:p8
adobecommerce
2.4.5:p9
adobecommerce
2.4.6
adobecommerce
2.4.6:p1
adobecommerce
2.4.6:p10
adobecommerce
2.4.6:p11
adobecommerce
2.4.6:p12
adobecommerce
2.4.6:p2
adobecommerce
2.4.6:p3
adobecommerce
2.4.6:p4
adobecommerce
2.4.6:p5
adobecommerce
2.4.6:p6
adobecommerce
2.4.6:p7
adobecommerce
2.4.6:p8
adobecommerce
2.4.6:p9
adobecommerce
2.4.7
adobecommerce
2.4.7:b1
adobecommerce
2.4.7:b2
adobecommerce
2.4.7:beta3
adobecommerce
2.4.7:p1
adobecommerce
2.4.7:p2
adobecommerce
2.4.7:p3
adobecommerce
2.4.7:p4
adobecommerce
2.4.7:p5
adobecommerce
2.4.7:p6
adobecommerce
2.4.7:p7
adobecommerce
2.4.8
adobecommerce
2.4.8:beta1
adobecommerce
2.4.8:beta2
adobecommerce
2.4.8:p1
adobecommerce
2.4.8:p2
adobecommerce
2.4.9:alpha1
adobecommerce
2.4.9:alpha2
adobecommerce_b2b
1.3.3
adobecommerce_b2b
1.3.3:p1
adobecommerce_b2b
1.3.3:p10
adobecommerce_b2b
1.3.3:p11
adobecommerce_b2b
1.3.3:p12
adobecommerce_b2b
1.3.3:p13
adobecommerce_b2b
1.3.3:p14
adobecommerce_b2b
1.3.3:p15
adobecommerce_b2b
1.3.3:p2
adobecommerce_b2b
1.3.3:p3
adobecommerce_b2b
1.3.3:p4
adobecommerce_b2b
1.3.3:p5
adobecommerce_b2b
1.3.3:p6
adobecommerce_b2b
1.3.3:p7
adobecommerce_b2b
1.3.3:p8
adobecommerce_b2b
1.3.3:p9
adobecommerce_b2b
1.3.4
adobecommerce_b2b
1.3.4:p1
adobecommerce_b2b
1.3.4:p10
adobecommerce_b2b
1.3.4:p11
adobecommerce_b2b
1.3.4:p12
adobecommerce_b2b
1.3.4:p13
adobecommerce_b2b
1.3.4:p14
adobecommerce_b2b
1.3.4:p2
adobecommerce_b2b
1.3.4:p3
adobecommerce_b2b
1.3.4:p4
adobecommerce_b2b
1.3.4:p5
adobecommerce_b2b
1.3.4:p6
adobecommerce_b2b
1.3.4:p7
adobecommerce_b2b
1.3.4:p8
adobecommerce_b2b
1.3.4:p9
adobecommerce_b2b
1.4.2
adobecommerce_b2b
1.4.2:p1
adobecommerce_b2b
1.4.2:p2
adobecommerce_b2b
1.4.2:p3
adobecommerce_b2b
1.4.2:p4
adobecommerce_b2b
1.4.2:p5
adobecommerce_b2b
1.4.2:p6
adobecommerce_b2b
1.4.2:p7
adobecommerce_b2b
1.5.2
adobecommerce_b2b
1.5.2:p1
adobecommerce_b2b
1.5.2:p2
adobecommerce_b2b
1.5.3:alpha1
adobecommerce_b2b
1.5.3:alpha2
adobemagento
2.4.5
adobemagento
2.4.5:p1
adobemagento
2.4.5:p10
adobemagento
2.4.5:p11
adobemagento
2.4.5:p12
adobemagento
2.4.5:p13
adobemagento
2.4.5:p14
adobemagento
2.4.5:p2
adobemagento
2.4.5:p3
adobemagento
2.4.5:p4
adobemagento
2.4.5:p5
adobemagento
2.4.5:p6
adobemagento
2.4.5:p7
adobemagento
2.4.5:p8
adobemagento
2.4.5:p9
adobemagento
2.4.6
adobemagento
2.4.6:p1
adobemagento
2.4.6:p10
adobemagento
2.4.6:p11
adobemagento
2.4.6:p12
adobemagento
2.4.6:p2
adobemagento
2.4.6:p3
adobemagento
2.4.6:p4
adobemagento
2.4.6:p5
adobemagento
2.4.6:p6
adobemagento
2.4.6:p7
adobemagento
2.4.6:p8
adobemagento
2.4.6:p9
adobemagento
2.4.7
adobemagento
2.4.7:b1
adobemagento
2.4.7:b2
adobemagento
2.4.7:beta3
adobemagento
2.4.7:p1
adobemagento
2.4.7:p2
adobemagento
2.4.7:p3
adobemagento
2.4.7:p4
adobemagento
2.4.7:p5
adobemagento
2.4.7:p6
adobemagento
2.4.7:p7
adobemagento
2.4.8
adobemagento
2.4.8:beta1
adobemagento
2.4.8:beta2
adobemagento
2.4.8:p1
adobemagento
2.4.8:p2
adobemagento
2.4.9:alpha1
adobemagento
2.4.9:alpha2
𝑥
= Vulnerable software versions