Skip to content
RequestGuard Vulnerabilities
Pricing

magento/project-community-edition

eCommerce Platform for Growth (Community Edition)

Composer latest 2.0.2 OSL-3.0, AFL-3.0

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

2.0.2

Published advisories match this version

2

Known exploitation

CISA KEV match

CVE-2025-54236

3

Highest advisory severity

Critical

161 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

161
Show 75 more advisories
GHSA-gffx-9f36-r8wp Magento security mitigation bypass vulnerability
GHSA-724x-gqhv-9c5x Magento command injection vulnerability
GHSA-j2jp-58gv-g2pg Magento Security mitigation bypass vulnerability
GHSA-4f7x-gjqc-qqpg Magento command injection vulnerability
GHSA-c3m4-hxv9-4mxj Magento command injection vulnerability
GHSA-5jfg-phx7-7fxg Magento Open Source affected by Improper Input Validation
GHSA-wr57-3h2f-3q95 Magento affected by a server-side denial-of-service using a GraphQL field
GHSA-36xq-7w8w-xp68 Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension
GHSA-mx5m-j5xr-jg8c Magento vulnerable to file upload attack
GHSA-j46h-qjjv-cxfj Magento affected by remote code execution via a file upload
GHSA-5vw8-r55w-f4q4 Magento is affected by an improper input validation vulnerability
GHSA-qmq6-jpvg-j547 Magento is affected by an os command injection via the Data collection endpoint
GHSA-rhff-65hp-55rw Magento allows attackers to alter the price of items
GHSA-m8wx-whpp-q283 Magento improper authorization vulnerability
GHSA-7w95-qwhh-q9p3 Magento Path Traversal vulnerability via the `theme[preview_image]` parameter
GHSA-xvpx-6hh8-7h72 Magento XML Injection vulnerability in the 'City' field
GHSA-3x9x-vhqj-cv27 Magento XML Injection vulnerability in the Widgets Update Layout
GHSA-mmp7-8cg4-9wrg Magento Stored Cross-Site Scripting (XSS) vulnerability
GHSA-52fg-wjxm-pp44 Magento DOM-based Cross-Site Scripting (XSS) vulnerability
GHSA-7r99-8wqp-h7pc Magento Path Traversal vulnerability
GHSA-q628-54wg-4r5q Magento does not properly restrict excessive authentication attempts
GHSA-2ff6-837j-hg5x Magento OS Command ('OS Command Injection') vulnerability
GHSA-8frp-pxq2-3gpq Magento OS Command ('OS Command Injection') vulnerability
GHSA-r487-9vv5-75gg Magento Improper Authorization leading to security feature bypass
GHSA-5777-jj7p-mpqw Magento Cross-Site Request Forgery (CSRF) vulnerability
GHSA-xgfm-992v-h2hr Magento vulnerable to denial of service
GHSA-2768-5wmv-cfff Magento vulnerable to stored Cross-Site Scripting (XSS)
GHSA-69x9-xp2j-w8g8 Magento provides incorrect authorization through a security feature bypass
GHSA-7hrj-3c9x-xv5h Magento has incorrect authorization issue that leads to arbitrary file system read
GHSA-8mq8-c243-2335 Magento Cross-site Scripting vulnerability
GHSA-954p-ff72-327w Adobe Commerce Path Traversal
GHSA-vw47-79jv-3598 Adobe Commerce Improper Authorization vulnerability
GHSA-59vf-hjxc-f9c5 Magento Open Source allows Cross-Site Scripting (XSS)
GHSA-5xmp-7wg5-x68q Magento Open Source affected by Improper Input Validation
GHSA-h3g9-cwr6-hphx Magento Open Source allows SQL Injection
GHSA-rq36-9f5f-2gw7 Magento Open Source allows SQL Injection
GHSA-ggr8-3hwx-4f2m Magento Open Source allows SQL Injection
GHSA-grc6-r6f8-xj7c Magento Open Source allows Improper Authorization
GHSA-3j7w-jp46-9752 Magento Open Source allows Cross-Site Scripting (XSS)
GHSA-rpc7-gf58-v3x2 Magento Open Source allows Incorrect Authorization
GHSA-2444-8gj8-6fmx Magento Open Source allows XML Injection
GHSA-8884-7rm9-mrx4 Magento stored Cross-Site Scripting (XSS) vulnerability
GHSA-g3j6-9753-8mp2 Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-rjjw-g6hw-7pc9 Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-gc27-rvvm-q77r Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-fhw6-3mj5-w9gv Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-xwgx-8v72-4j5j Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-m4rg-mpp2-97px Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-36hw-x3cc-m258 Magento Improper Access Control vulnerability
GHSA-gjxp-46rq-wg4q Magento Stored Cross-Site Scripting (XSS) Vulnerability
GHSA-7gh6-f4jh-3crq Magento Violation of Secure Design Principles vulnerability in RMA PDF filename formats
GHSA-6988-g89m-27vf Magento stored cross-site scripting (XSS) in the customer address upload feature
GHSA-j2r4-2cr6-h3r3 Magento Signature verification bypass
GHSA-8wm7-h2qh-ff4c Magento authorization bypass vulnerability
GHSA-crv7-r357-gw3w Magento 2 Community Edition RCE Vulnerability
GHSA-h7qw-mxrm-c6h2 Unauthenticated crypto and weak IV in Magento\Framework\Encryption
GHSA-3g7m-g8qm-x6j5 Magento discloses sensitive information
GHSA-wgpr-9675-8r67 Magento discloses sensitive information via the Multishipping Module
GHSA-vrq2-w7r7-3fp2 Magento is affected by an improper authorization vulnerability
GHSA-x2v2-2jhp-c5hv Magento stored cross-site scripting vulnerability
GHSA-8gfq-m4cf-w975 Magento stored cross-site scripting vulnerability in the customer address upload feature
GHSA-3f97-7pgv-gmgr Magento affected by a business logic error in the placeOrder graphql mutation
GHSA-5g9f-7gqc-8hj4 Magento Improper Authorization vulnerability
GHSA-gvgf-pvh5-vjh4 Magento Improper Authorization vulnerability
GHSA-cjm6-8mw8-2f8c Magento Improper Authorization vulnerability
GHSA-qrh3-vxjg-h9h6 Magento Improper Authorization vulnerability
GHSA-8w5f-8992-g86j Magento Improper Authorization vulnerability
GHSA-qm77-mqf3-fmhq Magento Improper Authorization leads to security feature bypass
GHSA-4xmj-f664-hv98 Magento Improper Authorization leads to Security feature bypass
GHSA-gj93-84g5-mcjq Magento Improper Authorization Leading to Security feature bypass
GHSA-x6f9-hv9r-fgq4 Magento Improper Access Control Leads to Privilege escalation
GHSA-vhcq-4xrm-2cr2 Magento Improper Access Control leads to Security feature bypass
GHSA-74w7-cr4v-wf2v Magento Improper Access Control Leads to Privilege escalation
GHSA-4xgg-rw35-7mv5 Magento Improper Authorization leads to Security feature bypass
GHSA-6wq7-cg9h-mj6q Magento Improper Access Control leads to Security feature bypass