{"id":"CVE-2025-27400","aliases":["GHSA-5pxh-89cx-4668"],"url":"https://o3.security/vulnerability/CVE-2025-27400","summary":"Magento vulnerable to stored XSS in theme config fields","details":"Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Versions prior to 20.12.3 and 20.13.0 contain a vulnerability that allows script execution in the admin panel which could lead to cross-site scripting against authenticated admin users. The attack requires an admin user with configuration access, so in practicality it is not very likely to be useful given that a user with this level of access is probably already a full admin. Versions 20.12.3 and 20.13.0 contain a patch for the issue.","published":"2025-02-28T15:26:14.265Z","modified":"2026-08-08T03:48:11.951631253Z","cvss":{"score":2.9,"severity":"LOW","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"openmage/magento-lts","fixedVersion":"20.12.3"}],"fix":{"url":"https://github.com/OpenMage/magento-lts/commit/d307e5bf75729a2347dde0952fe9fd9fcd9c6aea","label":"OpenMage/magento-lts@d307e5b"},"references":[{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.12.3"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.13.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27400.json"},{"type":"ADVISORY","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-5pxh-89cx-4668"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27400"},{"type":"FIX","url":"https://github.com/OpenMage/magento-lts/commit/d307e5bf75729a2347dde0952fe9fd9fcd9c6aea"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:11.951631253Z"}}