CVE-2025-49555: Adobe Commerce
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where the victim is authenticated, potentially allowing unauthorized access or modification of sensitive data. Exploitation of this issue requires user interaction in that a victim must visit a malicious website or click on a crafted link. Scope is changed.
Affected products
- Adobe Commerce: before 2.4.4 (fixed in 2.4.4); version 2.4.4 only; version 2.4.5 only; version 2.4.6 only; version 2.4.7 only; version 2.4.8 only
- Adobe Commerce b2b: before 1.3.3 (fixed in 1.3.3); version 1.3.3 only; version 1.3.4 only; version 1.3.5 only; version 1.4.2 only; version 1.5.2 only; …
- Adobe Magento: before 2.4.5 (fixed in 2.4.5); version 2.4.5 only; version 2.4.6 only; version 2.4.7 only; version 2.4.8 only; version 2.4.9 only
Published 2025-08-12. Last modified 2026-06-17.