Exposição de Magento
CMS, Ecommerce346
score de exposição
33.657
sites usam
2
em exploração
30
críticos
Análise Vexday
Com 285 CVEs catalogadas e 2 entradas confirmadas no catálogo CISA KEV, o Magento apresenta taxa de exploração ativa acima da média geral do catálogo — 1,6 vez superior —, o que indica que vulnerabilidades nessa plataforma tendem a ser alvo real de agentes maliciosos com frequência desproporcional. O destaque de risco imediato é CVE-2022-24086, com EPSS de 0,992, sinalizando probabilidade extremamente elevada de exploração ativa. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), e os 28 registros de severidade crítica, somados a 10 novas CVEs nos últimos 90 dias, reforçam a necessidade de gestão contínua de patches para ambientes que executam esta plataforma.
CVEs
299 resultadosCVE-2022-24086CRITICALAdobe Commerce checkout improper input validation leads to remote code executionEPSS 99.1%KEVCVE-2026-45247CRITICALMirasvit Cache Warmer for Magento < 1.11.12 PHP Object InjectionEPSS 27.5%KEVCVE-2021-21029MEDIUMMagento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript ExecutionEPSS 84.7%CVE-2022-34258MEDIUMAdobe Commerce Stored XSS Arbitrary code executionEPSS 68.3%CVE-2023-22249MEDIUMAdobe Commerce Stored XSS Arbitrary code executionEPSS 57.4%CVE-2026-48356CRITICALAdobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 28.2%CVE-2026-47992HIGHAdobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)EPSS 19.9%CVE-2026-47996MEDIUMAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 19.9%CVE-2019-7139—An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data EPSS 17.7%CVE-2020-3716—Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted daEPSS 14.0%CVE-2022-35698CRITICALAdobe Commerce Stored XSS Arbitrary code executionEPSS 10.1%CVE-2026-47997MEDIUMAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 9.0%CVE-2021-21064MEDIUMMagento UPWARD-php Path traversal vulnerability via UPWARD ConnectorEPSS 8.5%CVE-2020-9664—Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could leadEPSS 8.4%CVE-2020-3718—Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. EPSS 7.5%CVE-2020-9631—Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation EPSS 7.4%CVE-2020-9632—Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation EPSS 7.4%CVE-2026-47999MEDIUMAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 7.1%CVE-2020-9691—Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitationEPSS 6.0%CVE-2020-24407CRITICALArbitrary code execution via file import functionalityEPSS 5.8%