tag
Magento
CVE-2025-54236
web
CRITICAL 9.1
KEV
EPSS 97%
Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)
Magento's customer address form exposes a file-upload field (customattributes[countryid]) at customer/addressfile/upload that is intended to accept a small file attachment (e.g. a document tied to a custom address attribute), guarded only by a per-request…
Patched
2026-07-06
CVE-2026-45247
web
CRITICAL 9.3
KEV
EPSS 28%
Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)
CVE-2026-45247 is a PHP object injection / insecure deserialization vulnerability in Mirasvit's Full Page Cache Warmer extension for Magento 2. The extension processes attacker-controlled data from the CacheWarmer cookie and passes it directly to PHP's native…
Unverified
2026-07-01