Release date, end-of-life schedule and full PHP, MySQL, OpenSearch and Redis system requirements for Magento Open Source 2.4.7-p6.
Magento Open Source 2.4.7-p6 was released on .
Its end of life is .
Its current support status is supported.
Release date
Jun 10, 2025
End of life
Apr 9, 2027
Status
supported
Distribution
Magento Open Source
2.4.7-p10 is the current release of the
2.4.7 line, published on
May 12, 2026. Requirements below are the ones documented for
2.4.7-p6 — for the stack to deploy today, see
Magento Open Source 2.4.7-p10.
APSB25-50criticalCVE-2025-47110fixed in this release
Stored cross-site scripting in the admin panel (CVE-2025-47110) that can be chained into arbitrary code execution when an administrator views the injected content. Fixed in the June 2025 patch set, including 2.4.8-p1.
Improper authorization (CVE-2025-27189) allowing a security feature bypass, published alongside the 2.4.8 general availability release. Older lines receive the fix through their April 2025 patch versions.
Improper authorization (CVE-2025-24434) that lets a low-privileged actor escalate privileges; Adobe rated it critical because exploitation does not require user interaction. Fixed in the February 2025 patch set.
Improper authentication (CVE-2024-45115) that allows privilege escalation without prior authentication. Part of the October 2024 patch set that followed the CosmicSting exploitation wave.
Unrestricted upload of a file with a dangerous type (CVE-2024-39397) allowing arbitrary code execution by an unauthenticated attacker; Adobe notes the exploit requires the Apache web server. Fixed in the August 2024 patch set.
XML external entity injection in the REST API (CVE-2024-34102), publicly known as CosmicSting. An unauthenticated attacker can read arbitrary files such as env.php and, chained with the glibc iconv bug CVE-2024-2961, execute code. Mass exploitation followed within weeks; Adobe also released an isolated patch for stores that could not upgrade.
APSB24-18criticalCVE-2024-20758, CVE-2024-20759inherited from 2.4.7
Improper input validation (CVE-2024-20758) enabling arbitrary code execution by an authenticated administrator, plus stored cross-site scripting (CVE-2024-20759). Published with the 2.4.7 general availability release and the April 2024 patch set.