All verified exploits

CVE-2025-54236 SessionReaper: Account Takeover & RCE via REST API Deserialization

Deterministic critical Magento CISA KEV Added cve-verified-cve-2025-54236

Detects Magento / Adobe Commerce instances where the REST API ServiceInputProcessor accepts nested objects in guest checkout endpoints, enabling unauthenticated session takeover and remote code execution via DI traversal + session poisoning. Affects all versions through 2.4.7-p7, 2.4.8-p2, and 2.4.9-alpha2.

Is your app exploitable through CVE-2025-54236?

Scan your domain free