Feed live

Magento vulnerabilities - every known CVE across Magento and Adobe Commerce

Magento and Adobe Commerce run large-scale retail deployments, so CVEs here are tracked with particular attention to PCI-relevant checkout and admin-panel flaws.

Total CVEs tracked
344,178
All time
Critical · Active
11,533
CVSS ≥ 9.0
New · 14 days
2,689
Newly disclosed
Feed last synced
3 hrs ago
Data freshness

magento security

Every published CVE affecting magento

This list contains every CVE that names magento as an affected product. Records come from the official CVE feeds maintained by MITRE and NIST. Each record includes a CVSS severity score, the affected version range, and a link to the full NVD entry. New records usually appear here within minutes of publication.

Third-party plugins, extensions, and add-ons built on top of magento are included alongside the core product. In most CMS ecosystems, the majority of CVEs come from the extension layer rather than the core application itself. Searching by component name is just as important as searching by platform name.

Understanding CVSS scores

Severity ratings explained

Every CVE has a CVSS 3.x score from 0 to 10. The score is based on how the vulnerability can be reached (over the network or locally), how complex the exploit is, what access an attacker needs beforehand, whether a victim has to do something first, and the impact on confidentiality, integrity, and availability if the attack succeeds.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact

Search by component name, vendor, or keyword to filter this list. Click any CVE ID to see the full record. If your installed version falls within the affected range, update immediately or check the vendor's security advisory.

Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-53787 critical 9.3/10 Jun 12, 2026 1mo ago
CVE-2026-45247 critical 9.3/10 May 26, 2026 2mo ago
CVE-2026-42207 medium 6.1/10 May 15, 2026 2mo ago
CVE-2026-42155 critical 9.3/10 May 15, 2026 2mo ago
CVE-2026-42458 medium 5.3/10 May 15, 2026 2mo ago
CVE-2026-5603 medium 4.8/10 Apr 5, 2026 4mo ago
CVE-2026-25523 medium 5.3/10 Feb 4, 2026 6mo ago
CVE-2025-58669 medium 5.9/10 Sep 22, 2025 10mo ago
CVE-2024-41676 medium 4.1/10 Jul 29, 2024 2y ago
CVE-2023-34379 medium 5.4/10 Jan 17, 2024 2y ago
CVE-2023-38220 high 7.5/10 Oct 13, 2023 2y ago
CVE-2023-41879 high 7.5/10 Sep 11, 2023 2y ago
CVE-2021-36036 high 7.2/10 Sep 6, 2023 2y ago
CVE-2021-36021 high 7.2/10 Sep 6, 2023 2y ago
CVE-2021-36023 critical 9.1/10 Sep 6, 2023 2y ago
CVE-2022-42344 high 8.8/10 Oct 20, 2022 3y ago
CVE-2021-28567 medium 5.0/10 Sep 8, 2021 4y ago
CVE-2021-28566 low 3.7/10 Sep 8, 2021 4y ago
CVE-2021-36044 high 7.5/10 Sep 1, 2021 4y ago
CVE-2021-36027 medium 6.5/10 Sep 1, 2021 4y ago
CVE-2021-36043 high 8.0/10 Sep 1, 2021 4y ago
CVE-2021-36042 critical 9.1/10 Sep 1, 2021 4y ago
CVE-2021-36030 high 7.5/10 Sep 1, 2021 4y ago
CVE-2021-36041 critical 9.1/10 Sep 1, 2021 4y ago
CVE-2021-36040 critical 9.1/10 Sep 1, 2021 4y ago
CVE-2021-36025 critical 9.1/10 Sep 1, 2021 4y ago
CVE-2021-36020 high 8.2/10 Sep 1, 2021 4y ago
CVE-2021-36035 critical 9.1/10 Sep 1, 2021 4y ago
CVE-2021-36024 critical 9.1/10 Sep 1, 2021 4y ago
CVE-2021-36031 high 7.2/10 Sep 1, 2021 4y ago
Page 1
Prev 1 2