Known Vulnerabilities for Magento by Magentocommerce
Listed below are 2 of the newest known vulnerabilities associated with "Magento" by "Magentocommerce".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53787 json | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability th... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-45247 json | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allow... | Not Provided | 2026-05-26 | 2026-06-03 |
| CVE-2026-42458 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-05-15 | 2026-05-15 |
| CVE-2026-42207 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-05-15 | 2026-05-15 |
| CVE-2026-42155 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-05-15 | 2026-05-15 |
| CVE-2023-34379 json | Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: ... | Not Provided | 2024-01-17 | 2026-04-28 |
| CVE-2022-35501 json | Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplica... | Not Provided | 2022-11-23 | 2026-07-09 |
| CVE-2012-6091 json | Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability. | 7.5 - HIGH | 2020-02-13 | 2020-02-21 |
| CVE-2011-5240 json | Not Provided | 2012-11-06 | 2026-04-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Magentocommerce | Magento | 1.7.0.2 | |||
| Application | Magentocommerce | Magento | 1.7.0.1 | |||
| Application | Magentocommerce | Magento | 1.7.0.0 | |||
| Application | Magentocommerce | Magento | 1.7.0.0 | |||
| Application | Magentocommerce | Magento | 1.7.0.0 | |||
| Application | Magentocommerce | Magento | 1.7.0.0 | |||
| Application | Magentocommerce | Magento | 1.6.2 | |||
| Application | Magentocommerce | Magento | 1.6.1.0 | |||
| Application | Magentocommerce | Magento | 1.6.1.0 | |||
| Application | Magentocommerce | Magento | 1.6.1.0 | |||
| Application | Magentocommerce | Magento | 1.6.1.0 | |||
| Application | Magentocommerce | Magento | 1.6.0.0 | |||
| Application | Magentocommerce | Magento | 1.6.0.0 | |||
| Application | Magentocommerce | Magento | 1.6.0.0 | |||
| Application | Magentocommerce | Magento | 1.6.0.0 | |||
| Application | Magentocommerce | Magento | 1.5 |