Stored Cross-Site Scripting Vulnerability in Adobe Commerce Products
CVE-2025-47110

9.1CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 June 2025

What is CVE-2025-47110?

Adobe Commerce products are susceptible to a stored XSS vulnerability that allows high-privilege attackers to inject harmful JavaScript into vulnerable form fields. This could result in the execution of malicious scripts in users' browsers when they access affected pages, posing significant risks to website security and user data integrity. It's crucial for administrators to review and update their systems to mitigate this risk.

Affected Version(s)

Adobe Commerce 0 <= 2.4.4-p13

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47110 : Stored Cross-Site Scripting Vulnerability in Adobe Commerce Products