Magento's vulnerability footprint centers on a narrowly scoped but globally deployed e-commerce platform and its ecosystem extensions, making it a prominent attack surface despite a small product count. The vendor's disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across its core Magento product line and associated modules such as Advanced Newsletter and Upward connectors. The exposure is dominated by web-application-layer weakness classes—notably cross-site scripting, SQL injection, CSRF, and authorization-bypass flaws—that are endemic to e-commerce systems handling user input, session state, and privilege boundaries. Defenders should treat Magento patches as high-priority for internet-facing storefronts and monitor both core platform and third-party extension releases, as the architecture's plugin model multiplies the effective attack surface; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Magento over time
Signals from CVEs in this vendor scope (224 CVEs).
224 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4010CRITICAL Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data. | Jan 23, 2017 | 9.8 | 91 | NO | YES |
CVE-2021-21029MEDIUM Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful | Feb 11, 2021 | 4.8 | 61 | NO | NO |
CVE-2015-1397MEDIUM SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 | Apr 29, 2015 | 6.5 | 56 | NO | YES |
CVE-2022-34258MEDIUM Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abuse | Aug 16, 2022 | 4.8 | 54 | NO | NO |
CVE-2019-7139CRITICAL An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento | Apr 10, 2019 | 9.8 | 50 | NO | YES |
CVE-2020-9664CRITICAL Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution. | Jul 22, 2020 | 9.8 | 34 | NO | NO |
CVE-2020-9576CRITICAL Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation cou | Jun 26, 2020 | 9.8 | 34 | NO | NO |
CVE-2020-9632CRITICAL Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploit | Jun 26, 2020 | 9.8 | 33 | NO | NO |
CVE-2020-9631CRITICAL Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploit | Jun 26, 2020 | 9.8 | 33 | NO | NO |
CVE-2020-9580CRITICAL Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploit | Jun 26, 2020 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (224 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magento.
Media articles that mention a CVE ID that affects a product developed by Magento — matched by CVE ID, not by vendor name.