Exposição de Magento

CMS, Ecommerce
346
score de exposição
33.657
sites usam
2
em exploração
30
críticos
Análise Vexday

Com 285 CVEs catalogadas e 2 entradas confirmadas no catálogo CISA KEV, o Magento apresenta taxa de exploração ativa acima da média geral do catálogo — 1,6 vez superior —, o que indica que vulnerabilidades nessa plataforma tendem a ser alvo real de agentes maliciosos com frequência desproporcional. O destaque de risco imediato é CVE-2022-24086, com EPSS de 0,992, sinalizando probabilidade extremamente elevada de exploração ativa. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), e os 28 registros de severidade crítica, somados a 10 novas CVEs nos últimos 90 dias, reforçam a necessidade de gestão contínua de patches para ambientes que executam esta plataforma.

CVEs

299 resultados
CVE-2020-9583Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vuEPSS 5.7%CVE-2020-9576Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vuEPSS 5.7%CVE-2020-9578Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vuEPSS 5.7%CVE-2020-9582Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vuEPSS 5.7%CVE-2021-21030HIGHMagento Commerce Stored Cross-site Scripting Could Lead To Arbitrary Javascript ExecutionEPSS 5.6%CVE-2026-53787CRITICALAmasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File UploadEPSS 5.2%CVE-2020-9580Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation EPSS 5.0%CVE-2020-9579Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation EPSS 5.0%CVE-2020-9587Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypasEPSS 5.0%CVE-2020-9585Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth secEPSS 4.9%CVE-2021-21016CRITICALMagento Commerce Unauthorized Data Modification Could Lead to Arbitrary Code ExecutionEPSS 4.7%CVE-2022-34253CRITICALAdobe Commerce XML Injection Arbitrary code executionEPSS 4.3%CVE-2021-21014CRITICALMagento Commerce Arbitrary Folder Empty Could Lead To Arbitrary Code ExecutionEPSS 4.2%CVE-2020-9689Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to aEPSS 4.1%CVE-2021-21018CRITICALMagnto Commerce Unauthorized Data Modification Could Lead To Arbitrary Code ExecutionEPSS 4.1%CVE-2020-9630Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic errorEPSS 4.0%CVE-2021-21012MEDIUMMagento Commerce Insecure Direct Object Reference Vulnerability Could Lead To Sensitive Information DisclosureEPSS 4.0%CVE-2020-9692Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation couEPSS 3.8%CVE-2021-21019CRITICALMagento Commerce XML Injection Could Lead To Remote Code ExecutionEPSS 3.6%CVE-2021-36022CRITICALMagento Commerce Widgets Update Layout XML Injection Vulnerability Could Lead To Remote Code ExecutionEPSS 3.4%