Cyber Resilience

CVE-2025-24425

Adobe Commerce ≤ 2.4.4

Published
11 February 2025
Modified
05 March 2025
Patch / advisory
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score 0.0062 47th percentile
Risk Priority 45 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2025-24425 is a medium-severity an unspecified weakness vulnerability in Adobe Commerce. Its CVSS base score is 5.3 (Medium).

Operationally, ranked at the 47th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to circumvent intended security mechanisms by manipulating the…

more

logic of the application's operations causing limited data modification. Exploitation of this issue does not require user interaction.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-29294Same product: Adobe Commerce
CVE-2024-45121Same product: Adobe Commerce
CVE-2026-34645Same product: Adobe Commerce
CVE-2026-21296Same product: Adobe Commerce
CVE-2025-43586Same product: Adobe Commerce
CVE-2025-27206Same product: Adobe Commerce
CVE-2024-45123Same product: Adobe Commerce
CVE-2026-21294Same product: Adobe Commerce
CVE-2025-24411Same product: Adobe Commerce
CVE-2025-24412Same product: Adobe Commerce

Affected Assets

adobe
commerce
2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8 · ≤ 2.4.4
adobe
commerce b2b
1.3.3, 1.3.4, 1.3.5, 1.4.2, 1.5.0 · ≤ 1.3.3
adobe
magento
2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8 · ≤ 2.4.4

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References