Libraries tagged by CVE-2025-54236

deployecommerce/module-prevent-customer-address-file-upload

9 Favers
4764 Downloads

A Magento2 extension that prevents file uploads to the /customer/address_file/upload endpoint.

Go to Download


wubinworks/module-session-reaper-patch

3 Favers
498 Downloads

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.

Go to Download


qoliber/magento-open-source-security

0 Favers
59 Downloads

Magento 2 security modules for Qoliber open source patches and fixes.

Go to Download