vulnti.work

Adobe Commerce and Magento Improper Input Validation Vulnerability

High Listed in CISA KEV
CVECVE-2025-54236
First seen2025-10-24 00:00 UTC
Disclosed2025-10-24 00:00 UTC
Last updated2026-07-14 20:15 UTC
Channel statuspending_review

Summary

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Adobe:Commerce and Magento

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV