Magento
Vendor:
First CVE: Oct 21, 2020 · Active for 5 years
18
Total CVEs
More Total CVEs than 93% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Magento over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2020
5 years ago
Most Recent CVE
Apr 20, 2026
97 days ago
CVE Severity & Scoring
Magento18 CVEs
33%
61%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required3 (16.7%)
Privileges Required
Low3 (16.7%)
High9 (50.0%)
None6 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40488HIGH Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwar | Apr 20, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-25524HIGH Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwar | Apr 20, 2026 | 8.1 | 29 | NO | NO |
CVE-2021-41144HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20 | Jan 27, 2023 | 8.8 | 28 | NO | NO |
CVE-2021-21426CRITICAL Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by | Apr 21, 2021 | 9.8 | 28 | NO | NO |
CVE-2023-23617HIGH OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 | Jan 28, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-41231HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to | Jan 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-41143HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4 | Jan 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-39217HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 a | Jan 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-32759HIGH OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for adm | Aug 27, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-21427HIGH Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administra | Apr 21, 2021 | 7.2 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Magento
Top CWEs
Versions
No cataloged versions.