Published Jun 10, 2025.
Stored cross-site scripting in the admin panel (CVE-2025-47110) that can be chained into arbitrary code execution when an administrator views the injected content. Fixed in the June 2025 patch set, including 2.4.8-p1.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2025-47110 | 9.1 | cross-site-scripting-stored | arbitrary-code-execution | — |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB25-50
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →