CVE-2025-54236
KEVCRITICAL 9.1EPSS 94.5%
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
- CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS
- 94.53% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-10-24
- Nuclei
- critical
- Published
- 2025-09-09
- Updated
- 2025-10-24
Proof-of-concept exploits (5)
- https://nullsecurityx.codes/cve-2025-54236-sessionreaper-unauthenticated-rce-in-magento
- Baba01hacker666/cve-2025-54236
- Dx3iZ/CVE-2025-54236
- Jenderal92/magento-upload-auto-submit-zoneh
- alexb616/SessionReaper-CVE-2025-54236