PT-2025-42200 · Adobe · Commerce

Published

2025-10-14

·

Updated

2025-10-20

·

CVE-2025-54266

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions 2.4.4-p15 and earlier Adobe Commerce versions 2.4.5-p14 Adobe Commerce versions 2.4.6-p12 Adobe Commerce versions 2.4.7-p7 Adobe Commerce versions 2.4.8-p2 Adobe Commerce versions 2.4.9-alpha2
Description The software is susceptible to a stored Cross-Site Scripting (XSS) issue. A high-privileged attacker could inject malicious scripts into vulnerable form fields. Execution of this script occurs in a victim’s browser when they access the page containing the vulnerable field. User interaction is required for exploitation, specifically, a victim must browse to the page containing the vulnerable field.
Recommendations Update Adobe Commerce to a version later than 2.4.4-p15. Update Adobe Commerce to a version later than 2.4.5-p14. Update Adobe Commerce to a version later than 2.4.6-p12. Update Adobe Commerce to a version later than 2.4.7-p7. Update Adobe Commerce to a version later than 2.4.8-p2. Update Adobe Commerce to a version later than 2.4.9-alpha2.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54266
GHSA-PCRX-R49H-X2W5

Affected Products

Commerce