Skip to content
RequestGuard Vulnerabilities
Pricing

magento/community-edition

Magento 2 (Open Source)

Composer latest 2.4.8-p5 OSL-3.0, AFL-3.0
One or more sources did not complete this lookup. Each affected section identifies the unavailable source.

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

2.4.8-p5

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

360 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

360
GHSA-wh92-6q6g-px7j critical CISA KEV

Magento Community Edition Improper Input Validation vulnerability

Affected range

ECOSYSTEM: introduced 0; last affected 2.4.5-p14ECOSYSTEM: introduced 2.4.6-p1; last affected 2.4.6-p12ECOSYSTEM: introduced 2.4.9-alpha1; last affected 2.4.9-alpha2ECOSYSTEM: introduced 2.4.7-beta1; last affected 2.4.7-p7ECOSYSTEM: introduced 2.4.8-beta1; last affected 2.4.8-p2
GHSA-f8fv-f786-9933 critical CISA KEV

Magento improper input validation vulnerability

Affected range

ECOSYSTEM: introduced 2.3.3-p1; fixed 2.3.7-p3ECOSYSTEM: introduced 2.4.0; fixed 2.4.3-p2

Fixed versions: 2.3.7-p3, 2.4.3-p2

GHSA-m8cj-3v68-3cxj critical CISA KEV

Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability

Affected range

ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p6ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p8ECOSYSTEM: introduced 0; fixed 2.4.4-p9

Fixed versions: 2.4.6-p6, 2.4.5-p8, 2.4.4-p9

Magento XML Injection vulnerability in the Widgets Module

Affected range

ECOSYSTEM: introduced 0; fixed 2.3.7-p4ECOSYSTEM: introduced 2.4.4; fixed 2.4.5ECOSYSTEM: introduced 2.4.0; fixed 2.4.3-p3

Fixed versions: 2.3.7-p4, 2.4.5, 2.4.3-p3

Magento executes code via the API File Option Upload Extension

Affected range

ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2ECOSYSTEM: introduced 0; fixed 2.3.7-p1

Fixed versions: 2.4.2-p2, 2.3.7-p1

Magento is affected by an improper input validation vulnerability while saving a customer's details

Affected range

ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2

Fixed versions: 2.3.7-p1, 2.4.2-p2

Magento XML Injection vulnerability in the Widgets Module

Affected range

ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2

Fixed versions: 2.3.7-p1, 2.4.2-p2

Magento affected by remote code execution vulnerability in the CMS page scheduled update feature

Affected range

ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2

Fixed versions: 2.3.7-p1, 2.4.2-p2

Magento improper access control vulnerability within Magento's Media Gallery Upload workflow

Affected range

ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2

Fixed versions: 2.3.7-p1, 2.4.2-p2

Magento XML Injection vulnerability in the Widgets Update Layout

Affected range

ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2

Fixed versions: 2.3.7-p1, 2.4.2-p2

Magneto contains stored XSS vulnerability

Affected range

ECOSYSTEM: introduced 2.4.8-beta1; fixed 2.4.8-p1ECOSYSTEM: introduced 2.4.7-beta1; fixed 2.4.7-p6ECOSYSTEM: introduced 0; fixed 2.4.5-p13ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p11

Fixed versions: 2.4.8-p1, 2.4.7-p6, 2.4.5-p13, 2.4.6-p11

Magento Open Source allows OS Command Injection

Affected range

ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p4ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p6ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p7

Fixed versions: 2.4.6-p4, 2.4.5-p6, 2.4.4-p7

Magento Open Source allows Cross-Site Scripting (XSS)

Affected range

ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p4ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p6ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p7

Fixed versions: 2.4.6-p4, 2.4.5-p6, 2.4.4-p7

Magento Open Source allows Improper Input Validation

Affected range

ECOSYSTEM: introduced 2.4.7-beta1; fixed 2.4.7ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p5ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p7ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p8

Fixed versions: 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8

Magento Open Source allows Improper Neutralization of Special Elements Used

Affected range

ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p2ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p4ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p5

Fixed versions: 2.4.6-p2, 2.4.5-p4, 2.4.4-p5

Magento Open Source allows Improper Neutralization of Special Elements Used

Affected range

ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p3ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p4

Fixed versions: 2.4.5-p3, 2.4.4-p4

Improper Authorization vulnerability in Magento and Adobe Commerce

Affected range

ECOSYSTEM: introduced 2.4.8-beta1; fixed 2.4.8-beta2ECOSYSTEM: introduced 2.4.7-beta1; fixed 2.4.7-p4ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p9ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p11ECOSYSTEM: introduced 0; fixed 2.4.4-p12

Fixed versions: 2.4.8-beta2, 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12

Show 75 more advisories
GHSA-55gv-hfg3-hwjq Magento Defense-in-depth security mitigation vulnerability
GHSA-c55h-7q4j-g6rq Magento command injection vulnerability
GHSA-5j4w-v87m-8r65 Magento business logic error vulnerability
GHSA-6w29-x5j4-qhrw Magento security mitigation bypass vulnerability
GHSA-gffx-9f36-r8wp Magento security mitigation bypass vulnerability
GHSA-724x-gqhv-9c5x Magento command injection vulnerability
GHSA-j2jp-58gv-g2pg Magento Security mitigation bypass vulnerability
GHSA-4f7x-gjqc-qqpg Magento command injection vulnerability
GHSA-c3m4-hxv9-4mxj Magento command injection vulnerability
GHSA-vpg9-gq7j-mxqg Magento 2 Community Edition RCE Vulnerability
GHSA-xgcp-59g2-wm8g Magento 2 Community Edition Insecure Component
GHSA-x9p7-vgp2-9pq2 Magento security bypass vulnerability
GHSA-vrp3-wc28-qg2h Magento Security mitigation bypass vulnerability
GHSA-5gmh-85x8-5cx7 Magento remote code execution (RCE), Cross-Site Scripting (XSS) and other vulnerabilities
GHSA-8j7c-682x-r9f2 Magento RCE,XSS and other vulnerabilities
GHSA-prpf-cj87-hwvr Magento Patch SUPEE-10752 - Multiple security enhancements vulnerabilities
GHSA-f7q4-9gwv-6774 Magento Open Source Improper Authentication vulnerability
GHSA-8mwx-wpp4-5xh4 Magento Broken authentication and session managememt
GHSA-cv25-3pxr-4q7x Magento Open Source Security Advisory: Patch SUPEE-10975
GHSA-26hq-7286-mg8f Magento Patch SUPEE-9652 - Remote Code Execution using mail vulnerability
GHSA-6wm4-3rjj-c8xx Magento Security enhancements that help close RCE,XSS,CSRF and other vulnerabilities
GHSA-9wc9-498w-h8xv Magento deserialization vulnerability
GHSA-4j6w-9rf8-hg7r Magento 2 Community Edition SQLi Vulnerability
GHSA-rv48-v862-mp92 Magento OS Command Injection
GHSA-mw95-gmw4-883p Magento XML injection in the Widgets module
GHSA-8p5c-f836-m4h7 Magento 2 Community Edition XML Injection
GHSA-3q5x-7mxp-rp6j Remote code execution via vulnerable Symphony dependecy injection
GHSA-rj4f-cp4v-hvcv Magento Blind SQL Injection in the Search module
GHSA-fx9g-g9q6-x3jx Magento Path Traversal vulnerability
GHSA-5jfg-phx7-7fxg Magento Open Source affected by Improper Input Validation
GHSA-x95x-f4g9-mm85 Magento Improper Access Control vulnerability
GHSA-r7mm-grf3-5fjv Magento Improper Authorization vulnerability
GHSA-297f-r9w7-w492 Magento Improper input validation vulnerability
GHSA-wr57-3h2f-3q95 Magento affected by a server-side denial-of-service using a GraphQL field
GHSA-36xq-7w8w-xp68 Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension
GHSA-mx5m-j5xr-jg8c Magento vulnerable to file upload attack
GHSA-j46h-qjjv-cxfj Magento affected by remote code execution via a file upload
GHSA-5vw8-r55w-f4q4 Magento is affected by an improper input validation vulnerability
GHSA-qmq6-jpvg-j547 Magento is affected by an os command injection via the Data collection endpoint
GHSA-rhff-65hp-55rw Magento allows attackers to alter the price of items
GHSA-m8wx-whpp-q283 Magento improper authorization vulnerability
GHSA-7w95-qwhh-q9p3 Magento Path Traversal vulnerability via the `theme[preview_image]` parameter
GHSA-xvpx-6hh8-7h72 Magento XML Injection vulnerability in the 'City' field
GHSA-3x9x-vhqj-cv27 Magento XML Injection vulnerability in the Widgets Update Layout
GHSA-mmp7-8cg4-9wrg Magento Stored Cross-Site Scripting (XSS) vulnerability
GHSA-52fg-wjxm-pp44 Magento DOM-based Cross-Site Scripting (XSS) vulnerability
GHSA-7r99-8wqp-h7pc Magento Path Traversal vulnerability
GHSA-q628-54wg-4r5q Magento does not properly restrict excessive authentication attempts
GHSA-2ff6-837j-hg5x Magento OS Command ('OS Command Injection') vulnerability
GHSA-8frp-pxq2-3gpq Magento OS Command ('OS Command Injection') vulnerability
GHSA-r487-9vv5-75gg Magento Improper Authorization leading to security feature bypass
GHSA-5777-jj7p-mpqw Magento Cross-Site Request Forgery (CSRF) vulnerability
GHSA-xgfm-992v-h2hr Magento vulnerable to denial of service
GHSA-2768-5wmv-cfff Magento vulnerable to stored Cross-Site Scripting (XSS)
GHSA-69x9-xp2j-w8g8 Magento provides incorrect authorization through a security feature bypass
GHSA-7hrj-3c9x-xv5h Magento has incorrect authorization issue that leads to arbitrary file system read
GHSA-8mq8-c243-2335 Magento Cross-site Scripting vulnerability
GHSA-954p-ff72-327w Adobe Commerce Path Traversal
GHSA-vw47-79jv-3598 Adobe Commerce Improper Authorization vulnerability
GHSA-59vf-hjxc-f9c5 Magento Open Source allows Cross-Site Scripting (XSS)
GHSA-5xmp-7wg5-x68q Magento Open Source affected by Improper Input Validation
GHSA-h3g9-cwr6-hphx Magento Open Source allows SQL Injection
GHSA-rq36-9f5f-2gw7 Magento Open Source allows SQL Injection
GHSA-ggr8-3hwx-4f2m Magento Open Source allows SQL Injection
GHSA-grc6-r6f8-xj7c Magento Open Source allows Improper Authorization
GHSA-3j7w-jp46-9752 Magento Open Source allows Cross-Site Scripting (XSS)
GHSA-rpc7-gf58-v3x2 Magento Open Source allows Incorrect Authorization
GHSA-2444-8gj8-6fmx Magento Open Source allows XML Injection
GHSA-8884-7rm9-mrx4 Magento stored Cross-Site Scripting (XSS) vulnerability
GHSA-g3j6-9753-8mp2 Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-rjjw-g6hw-7pc9 Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-gc27-rvvm-q77r Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-fhw6-3mj5-w9gv Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-xwgx-8v72-4j5j Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-m4rg-mpp2-97px Magento Stored Cross-Site Scripting (XSS) Vulnerability