Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • H
Access Restriction Bypass
magento/community-edition<2.3.6-p1>=2.4.0, <2.4.2Composer10 Feb 2021
  • M
Session Fixation
magento/community-edition<2.3.6-p1>=2.4.0, <2.4.2Composer10 Feb 2021
  • M
Insecure Direct Object Reference
magento/community-edition>=2.1.0, <2.1.17>=2.2.0, <2.2.8>=2.3.0, <2.3.1Composer25 Aug 2020
  • C
Remote Code Execution (RCE)
magento/community-edition>=2.3.0, <2.3.3Composer25 Aug 2020
  • M
Observable Timing Discrepancy
magento/community-edition<2.3.5-p2Composer29 Jul 2020
  • C
Cross-site Scripting (XSS)
magento/community-edition<2.3.5-p2Composer29 Jul 2020
  • H
Security Bypass
magento/community-edition<2.3.5-p2Composer29 Jul 2020
  • H
Directory Traversal
magento/community-edition<2.3.5-p2Composer29 Jul 2020
  • H
Cross-site Scripting (XSS)
magento/community-edition<1.9.4.4Composer29 May 2020
  • H
SQL Injection
magento/community-edition<1.9.4.4Composer29 May 2020
  • H
Arbitrary Code Execution
magento/community-edition<1.9.4.4Composer29 May 2020
  • H
Directory Traversal
magento/community-edition<1.9.4.4Composer29 May 2020
  • H
Cross-site Scripting (XSS)
magento/community-edition<1.9.4.4Composer29 May 2020
  • H
Deserialization of Untrusted Data
magento/community-edition<1.9.4.4Composer29 May 2020
  • H
Security Bypass
magento/community-edition<1.9.4.5Composer13 May 2020
  • H
Security Bypass
magento/community-edition<1.9.4.5Composer13 May 2020
  • M
Privilege Escalation
magento/community-edition<1.9.4.4Composer10 May 2020
  • H
Authorization Bypass
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • M
Command Injection
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • M
Arbitrary Code Execution
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Cross-site Scripting (XSS)
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Command Injection
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Improper Authorization
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Command Injection
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Arbitrary Code Execution
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Command Injection
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Arbitrary Code Execution
magento/community-edition<1.9.4.5Composer7 May 2020
  • H
Cross-site Scripting (XSS)
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • H
Cross-site Scripting (XSS)
magento/community-edition>=2.3.5, <2.3.5-p1<2.3.4-p2Composer7 May 2020
  • M
Signature Validation Bypass
magento/community-edition<1.9.4.5Composer6 May 2020