CRITICAL

APSB25-50: Security update available for Adobe Commerce

Published Jun 10, 2025.

Stored cross-site scripting in the admin panel (CVE-2025-47110) that can be chained into arbitrary code execution when an administrator views the injected content. Fixed in the June 2025 patch set, including 2.4.8-p1.

Published
Jun 10, 2025
Severity
critical
CVEs
1
Isolated patch
no

CVEs

CVEs in APSB25-50
CVE CVSS Type Impact Auth required
CVE-2025-47110 9.1 cross-site-scripting-stored arbitrary-code-execution

Fixed in

Magento Open Source
2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14
Adobe Commerce
2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14
Mage-OS

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB25-50