CVE-2025-27400
Magento LTS vulnerable to stored XSS in theme config fields
Description
As reported by [Aakash Adhikari](https://hackerone.com/dark_haxor), Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ### Impact A malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. 
How to fix CVE-2025-27400
To remediate CVE-2025-27400, upgrade the affected package to a fixed version below.
- —upgrade to 20.12.3 or later
Is CVE-2025-27400 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 20.12.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW2.9 | CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L |