CVE-2025-29722
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Summary
CVE-2025-29722 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Commercify v1.0. This issue grants attackers the ability to execute unauthorized actions on authenticated user accounts. The vulnerability stems from a lack of CSRF protection on sensitive endpoints, enabling potential malicious requests from untrusted sources. Successful exploitation could result in significant data manipulation or unintended system changes. Users and administrators are advised to update to the latest version of Commercify, which includes the necessary security enhancements.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.