CVE-2025-22384
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/01/2025
Last modified:
20/05/2025
Description
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:* | 5.2.2408 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



