Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2025-27189

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable application, which may disrupt service availability. Exploitation of this issue requires user interaction, typically in the form of clicking a malicious link or visiting an attacker-controlled website.

  • Published: Apr 8, 2025
  • Updated: May 1, 2025
  • CVE: CVE-2025-27189
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CWEs:

Software From Fixed in
adobe / commerce_b2b 1.4.2-p1 1.4.2-p1.x
adobe / commerce_b2b 1.4.2-p2 1.4.2-p2.x
adobe / commerce_b2b 1.4.2 1.4.2.x
adobe / commerce_b2b 1.3.5-p7 1.3.5-p7.x
adobe / commerce_b2b 1.3.4-p9 1.3.4-p9.x
adobe / commerce_b2b 1.3.4 1.3.4.x
adobe / commerce_b2b - 1.3.3
adobe / commerce_b2b 1.3.3 1.3.3.x
adobe / commerce_b2b 1.3.3-p10 1.3.3-p10.x
adobe / commerce_b2b 1.3.3-p11 1.3.3-p11.x
adobe / commerce_b2b 1.3.3-p12 1.3.3-p12.x
adobe / commerce_b2b 1.3.4-p10 1.3.4-p10.x
adobe / commerce_b2b 1.3.4-p11 1.3.4-p11.x
adobe / commerce_b2b 1.3.5 1.3.5.x
adobe / commerce_b2b 1.3.5-p8 1.3.5-p8.x
adobe / commerce_b2b 1.3.5-p9 1.3.5-p9.x
adobe / commerce_b2b 1.4.2-p3 1.4.2-p3.x
adobe / commerce_b2b 1.5.0 1.5.0.x
adobe / commerce_b2b 1.4.2-p4 1.4.2-p4.x
adobe / commerce_b2b 1.5.1 1.5.1.x