Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • H
Remote Code Execution
magento/community-edition>=2.1, <2.1.17>=2.2, <2.2.8>=2.3, <2.3.1Composer1 Apr 2019
  • H
Remote Code Execution
magento/community-edition>=2.1, <2.1.17>=2.2, <2.2.8>=2.3, <2.3.1Composer1 Apr 2019
  • H
Remote Code Execution
magento/community-edition>=2.1, <2.1.17>=2.2, <2.2.8>=2.3, <2.3.1Composer1 Apr 2019
  • H
Cross-site Scripting (XSS)
magento/community-edition>=2.1, <2.1.17>=2.2, <2.2.8>=2.3, <2.3.1Composer1 Apr 2019
  • H
SQL Injection
magento/community-edition>=2.1, <2.1.17>=2.2, <2.2.8>=2.3, <2.3.1Composer1 Apr 2019
  • H
Remote Code Execution (RCE)
magento/community-edition>=2.1, <2.1.17>=2.2, <2.2.8>=2.3, <2.3.1Composer31 Mar 2019
  • H
Remote Code Execution (RCE)
magento/community-edition>=2.1, <2.1.17>=2.2, <2.2.8>=2.3, <2.3.1Composer31 Mar 2019
  • C
SQL Injection
magento/community-edition>2.0.0, <2.1.17>2.2.0, <2.2.8>2.3.0, <2.3.1Composer30 Mar 2019
  • H
Insecure Encryption
magento/community-edition<2.2.5Composer19 Jul 2018
  • M
Improper Authorization
magento/core<2.3.6>=2.4.0, <2.4.1Composer23 Oct 2020
  • H
Remote Code Execution (RCE)
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • L
Information Exposure
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • M
Improper Authorization
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • M
Insufficient Validation
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • M
Improper Authorization
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • H
SQL Injection
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • H
Cross-site Scripting (XSS)
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • L
Improper Authorization
magento/core<2.3.6>=2.4.0, <2.4.1Composer18 Oct 2020
  • M
Cross-Site Request Forgery (CSRF)
magento/core<2.0.10>=2.1.0, <2.1.2Composer30 Jul 2020
  • H
Cross-site Scripting (XSS)
magento/core>=0.0.0Composer30 Jun 2020
  • H
Cross-site Scripting (XSS)
magento/core>=2.3.0, <2.3.3<2.2.10Composer29 May 2020
  • H
SQL Injection
magento/core>=2.3.0, <2.3.4<2.2.11Composer29 May 2020
  • H
Arbitrary Code Execution
magento/core>=2.3.0, <2.3.4<2.2.11Composer29 May 2020
  • H
Directory Traversal
magento/core>=2.3.0, <2.3.4<2.2.11Composer29 May 2020
  • H
Cross-site Scripting (XSS)
magento/core>=2.3.0, <2.3.4<2.2.11Composer29 May 2020
  • H
Deserialization of Untrusted Data
magento/core>=2.3.0, <2.3.4<2.2.11Composer29 May 2020
  • H
Security Bypass
magento/core<2.3.4-p2Composer13 May 2020
  • H
Security Bypass
magento/core<2.3.4-p2Composer13 May 2020
  • M
Privilege Escalation
magento/core<2.2.11>=2.3.0, <2.3.4Composer10 May 2020
  • H
Authorization Bypass
magento/core<1.9.4.5Composer7 May 2020