CVE-2025-29722: Yassmittal Commercify

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.

Affected products

Published 2025-04-17. Last modified 2026-06-17.