Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Improper Authorization
magento/project-community-edition>=0.0.0Composer20 Feb 2025
  • L
Cross-site Scripting (XSS)
openmage/magento-lts<20.12.3Composer7 Mar 2025
  • M
Cross-site Scripting
openmage/magento-lts<20.10.1Composer30 Jul 2024
  • M
Cross-site Scripting (XSS)
openmage/magento-lts<19.5.3>=20.0.0, <20.5.0Composer28 Feb 2024
  • H
Cross-site Scripting (XSS)
openmage/magento-lts<20.2.0Composer14 Dec 2023
  • H
Insecure Randomness
openmage/magento-lts<19.5.1>=20.0.0, <20.1.1Composer12 Sept 2023
  • L
Cross-site Request Forgery (CSRF)
openmage/magento-lts<19.4.22>=20.0.0, <20.0.19Composer27 Jan 2023
  • H
Arbitrary Code Execution
openmage/magento-lts<19.4.22>=20.0.0, <20.0.19Composer27 Jan 2023
  • H
Arbitrary Code Execution
openmage/magento-lts<19.4.22>=20.0.0, <20.0.19Composer27 Jan 2023
  • H
Arbitrary Code Execution
openmage/magento-lts<19.4.22>=20.0.0, <20.0.19Composer27 Jan 2023
  • M
Denial of Service (DoS)
openmage/magento-lts<19.4.22>=20.0.0, <20.0.19Composer27 Jan 2023
  • H
Arbitrary Command Execution
openmage/magento-lts<19.4.22>=20.0.0, <20.0.19Composer27 Jan 2023
  • M
Arbitrary File Upload
openmage/magento-lts>=20.0.0, <20.0.13<19.4.15Composer31 Aug 2021
  • H
Arbitrary Code Execution
openmage/magento-lts>=20.0.0, <20.0.13<19.4.15Composer31 Aug 2021
  • L
SQL Injection
openmage/magento-lts>=20.0.0, <20.0.10<19.4.13Composer26 Apr 2021
  • M
Deserialization of Untrusted Data
openmage/magento-lts>=20.0.0, <20.0.10<19.4.13Composer26 Apr 2021
  • H
Remote Code Execution (RCE)
openmage/magento-lts<19.4.9>=20.0.0, <20.0.5Composer21 Jan 2021
  • H
Unrestricted File Upload
openmage/magento-lts>=20.0.0, <20.0.5>=19.4.0, <19.4.9Composer21 Jan 2021
  • M
Arbitrary Code Execution
openmage/magento-lts>=20.0.0, <20.0.5>=19.4.0, <19.4.9Composer21 Jan 2021
  • M
Remote Code Execution (RCE)
openmage/magento-lts<19.4.8>=20.0.0, <20.0.4Composer23 Oct 2020
  • M
Cross-site Request Forgery (CSRF)
openmage/magento-lts<19.4.6>=20.0.0, <20.0.2Composer20 Aug 2020
  • M
Denial of Service (DoS)
@scandipwa/magento-scripts>=1.5.1 <1.5.3npm15 Jun 2021