📦 Magento Open Source

by Adobe

🔍 What is Magento Open Source?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-24093

CRITICAL CVSS 9.1 Sep 12, 2023

CVE-2022-24093 is an improper input validation vulnerability in Adobe Commerce (formerly Magento) that allows authenticated attackers to execute arbitrary code on affected systems. This affects Adobe ...

CVE-2021-36022

CRITICAL CVSS 9.1 Sep 1, 2021

This CVE describes an XML injection vulnerability in Magento Commerce that allows authenticated attackers with admin privileges to execute arbitrary code remotely. The vulnerability affects Magento Co...

CVE-2021-36025

CRITICAL CVSS 9.1 Sep 1, 2021

CVE-2021-36025 is an improper input validation vulnerability in Adobe Magento Commerce that allows authenticated attackers with admin privileges to upload specially crafted files and achieve remote co...

CVE-2023-22247

HIGH CVSS 7.5 Mar 27, 2023

CVE-2023-22247 is an XML injection vulnerability in Adobe Commerce that allows unauthenticated attackers to read arbitrary files from the server. This affects Adobe Commerce versions 2.4.4-p2 and earl...

CVE-2021-36020

HIGH CVSS 8.2 Sep 1, 2021

This CVE describes an XML injection vulnerability in Magento Commerce's 'City' field that allows unauthenticated attackers to execute arbitrary code remotely. It affects Magento Commerce versions 2.4....

CVE-2023-22250

MEDIUM CVSS 5.3 Mar 27, 2023

CVE-2023-22250 is an improper access control vulnerability in Adobe Commerce that allows attackers to bypass security features and potentially disrupt minor functionality. This affects Adobe Commerce ...