CVE-2025-24416
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
- Affected products
- Commerce
- Adobe Commerce
- < 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8
- CVSS 3.1
- 8.7 HIGH
- EPSS
- 0.7% (49th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2025-02-11
No indexed exploits for CVE-2025-24416 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-24416 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.