Cross-Site Scripting Vulnerability in Magento Long Term Support Admin Panel
CVE-2025-27400
What is CVE-2025-27400?
The Magento Long Term Support platform, which serves as a community-driven alternative to Magento Community Edition, has a cross-site scripting vulnerability present in versions prior to 20.12.3 and 20.13.1. This flaw allows an authenticated admin user to execute scripts within the admin panel. Although exploitation requires administrative access, making it less concerning in practical terms, it nonetheless poses a risk if compromised. Users are advised to upgrade to the patched versions to mitigate this security issue. For more information, consult the security advisory on GitHub.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
magento-lts < 20.12.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
