Exposición de Magento
CMS, Ecommerce346
score de exposición
33.657
sitios usan
2
en explotación
30
críticos
Análisis Vexday
Com 285 CVEs catalogadas e 2 entradas confirmadas no catálogo CISA KEV, o Magento apresenta taxa de exploração ativa acima da média geral do catálogo — 1,6 vez superior —, o que indica que vulnerabilidades nessa plataforma tendem a ser alvo real de agentes maliciosos com frequência desproporcional. O destaque de risco imediato é CVE-2022-24086, com EPSS de 0,992, sinalizando probabilidade extremamente elevada de exploração ativa. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), e os 28 registros de severidade crítica, somados a 10 novas CVEs nos últimos 90 dias, reforçam a necessidade de gestão contínua de patches para ambientes que executam esta plataforma.
CVEs
299 resultadosCVE-2020-9591—Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth secEPSS 3.4%CVE-2021-21025CRITICALMagento Commerce XML Injection Could Lead To Arbitrary Code ExecutionEPSS 3.3%CVE-2019-8159—A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user wEPSS 3.3%CVE-2021-21013HIGHMagento Commerce Insecure Direct Object Reference Could Lead To Information DisclosureEPSS 3.2%CVE-2020-3719—Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. SEPSS 3.2%CVE-2020-3717—Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. SEPSS 3.2%CVE-2021-36033CRITICALMagento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code ExecutionEPSS 3.1%CVE-2021-36031HIGHMagento Commerce Path Traversal In `theme[preview_image]` Parameter Could Lead To Remote Code ExecutionEPSS 3.1%CVE-2021-36028CRITICALMagento Commerce XML Injection Vulnerability Could Lead To Remote Code ExecutionEPSS 2.9%CVE-2021-36024CRITICALMagento Commerce Improper Neutralization of Special Elements Used In A CommandEPSS 2.9%CVE-2020-26285HIGHWidget instances allows a hacker to inject an executable file on the server on OpenMageEPSS 2.9%CVE-2021-36040CRITICALMagento Commerce Improper Input Validation Could Lead To Remote Code ExecutionEPSS 2.9%CVE-2021-21015HIGHMagento Commerce Unauthorized Data Modification Could Lead to Arbitrary Code ExecutionEPSS 2.9%CVE-2021-36035CRITICALMagento Commerce Stock Media Improper Input Validation Could Lead To Remote Code ExecutionEPSS 2.8%CVE-2021-36025CRITICALMagento Commerce Customer Edition Improper Input Validation Could Lead To Remote Code ExecutionEPSS 2.8%CVE-2021-21024CRITICALMagento Commerce Blind SQL Injection Could Lead To Unauthorized AccessEPSS 2.8%CVE-2021-36020HIGHMagento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code ExecutionEPSS 2.7%CVE-2020-9588—Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing dEPSS 2.5%CVE-2021-36029CRITICALMagento Commerce Improper Authorization Vulnerability Could Lead To Remote Code ExecutionEPSS 2.5%CVE-2021-36042CRITICALMagento Commerce API File Option Upload Extension Improper Input Validation Vulnerability Could Lead To Remote Code ExecutionEPSS 2.5%