Exposição de Magento

CMS, Ecommerce
435
score de exposição
33.253
sites usam
3
em exploração
34
críticos
Análise Vexday

Com 285 CVEs catalogadas e 2 entradas confirmadas no catálogo CISA KEV, o Magento apresenta taxa de exploração ativa acima da média geral do catálogo — 1,6 vez superior —, o que indica que vulnerabilidades nessa plataforma tendem a ser alvo real de agentes maliciosos com frequência desproporcional. O destaque de risco imediato é CVE-2022-24086, com EPSS de 0,992, sinalizando probabilidade extremamente elevada de exploração ativa. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), e os 28 registros de severidade crítica, somados a 10 novas CVEs nos últimos 90 dias, reforçam a necessidade de gestão contínua de patches para ambientes que executam esta plataforma.

CVEs

349 resultados
CVE-2022-24086CRITICALAdobe Commerce checkout improper input validation leads to remote code executionEPSS 99.2%KEVCVE-2026-45247CRITICALMirasvit Cache Warmer for Magento < 1.11.12 PHP Object InjectionEPSS 27.5%KEVCVE-2026-75650CRITICALAdobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)EPSS 2.1%KEVCVE-2021-21029MEDIUMMagento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript ExecutionEPSS 84.6%CVE-2022-34258MEDIUMAdobe Commerce Stored XSS Arbitrary code executionEPSS 68.5%CVE-2023-22249MEDIUMAdobe Commerce Stored XSS Arbitrary code executionEPSS 57.4%CVE-2026-71362CRITICALAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 24.5%CVE-2026-34648HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 22.6%CVE-2026-34650HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 15.9%CVE-2026-34649HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 14.4%CVE-2020-3716Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted daEPSS 14.0%CVE-2022-35698CRITICALAdobe Commerce Stored XSS Arbitrary code executionEPSS 10.9%CVE-2019-7139An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data EPSS 9.9%CVE-2021-21064MEDIUMMagento UPWARD-php Path traversal vulnerability via UPWARD ConnectorEPSS 8.5%CVE-2020-9664Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could leadEPSS 8.4%CVE-2020-3718Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. EPSS 7.5%CVE-2020-9631Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation EPSS 7.4%CVE-2020-9632Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation EPSS 7.4%CVE-2020-9691Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitationEPSS 6.0%CVE-2020-9576Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vuEPSS 5.7%