Libraries tagged by CVE-2025-54236
deployecommerce/module-prevent-customer-address-file-upload
9 Favers
4764 Downloads
4764 Downloads
A Magento2 extension that prevents file uploads to the /customer/address_file/upload endpoint.
wubinworks/module-session-reaper-patch
3 Favers
498 Downloads
498 Downloads
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
qoliber/magento-open-source-security
0 Favers
59 Downloads
59 Downloads
Magento 2 security modules for Qoliber open source patches and fixes.