Vulnerabilities
Summary — last 7 days
New vulnerabilities3,222▲ 222 vs. last week
Critical / high1,465▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)511▼ 31 vs. last week
480 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (5.3) | 0.25% | — | Openmage Magento | 4/20/2026 | 6/17/2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the shared wishlist add-to-cart endpoint authorizes access with a public `sharing_code`, but… | |
| Analyzed | Medium (4.9) | 0.65% | — | Openmage Magento | 4/20/2026 | 6/17/2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the Dataflow module in OpenMage LTS uses a weak blacklist filter (`str_replace('../', '',… | |
| Analyzed | High (8.1) | 0.71% | — | Openmage Magento | 4/20/2026 | 6/17/2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()` can trigger… | |
| Deferred | Low (1.9) | 1.1% | — | Elgentos Magento2-dev-mcpAI | 4/5/2026 | 7/24/2026 | A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the… | |
| Analyzed | High (8.1) | 0.45% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analyzed | Medium (6.8) | 0.64% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this… | |
| Analyzed | Medium (4.7) | 0.21% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have limited impact to the… | |
| Analyzed | High (8) | 0.30% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analyzed | Medium (5.3) | 0.30% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interaction. | |
| Analyzed | High (7.5) | 0.56% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of… | |
| Analyzed | Medium (4.3) | 0.35% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited… | |
| Analyzed | Medium (4.3) | 0.34% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited… | |
| Analyzed | Low (3.1) | 0.23% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user… | |
| Analyzed | Medium (5.5) | 0.24% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and… | |
| Analyzed | Medium (5.5) | 0.24% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and… | |
| Analyzed | Medium (5.4) | 0.26% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires… | |
| Analyzed | Medium (4.8) | 0.27% | — | Adobe MagentoAdobe CommerceAdobe Commerce B2B | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user… | |
| Analyzed | High (8.7) | 0.45% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analyzed | High (7.5) | 0.60% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of… | |
| Analyzed | Medium (5.3) | 0.29% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized view… | |
| Analyzed | Medium (4.3) | 0.26% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited… | |
| Analyzed | High (8.1) | 0.38% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analyzed | Medium (5.3) | 0.52% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 3/11/2026 | 8/28/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing limited impact to… | |
| Analyzed | Medium (5.3) | 0.39% | — | Openmage Magento | 2/4/2026 | 6/17/2026 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1. | |
| Analyzed | Medium (4.6) | 0.22% | — | Openmage Magento | 11/6/2025 | 6/17/2026 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable… |