Magento
This hub aggregates every CVE we track for Magento, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
427
CVEs tracked
48
Critical
150
High
4
In CISA KEV
Severity distribution
MEDIUM211HIGH150CRITICAL48LOW18
Monthly trend
22
1
0
0
23
0
4
0
6
0
6
1
5
1
0
0
1
19
4
15
0
14
1
9
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Magento.
- CVE-2026-76200Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)9.3
- CVE-2026-76201Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)9.3
- CVE-2026-77109Adobe Commerce | Incorrect Authorization (CWE-863)8.6
- CVE-2026-77110Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)7.6
- CVE-2026-77108Adobe Commerce | Incorrect Authorization (CWE-863)7.5
- CVE-2026-76202Adobe Commerce | Incorrect Authorization (CWE-863)8.2
- CVE-2026-77774Adobe Commerce | Incorrect Authorization (CWE-863)8.6
- CVE-2026-77111Adobe Commerce | Incorrect Authorization (CWE-863)8.7
- CVE-2026-75650Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)KEV10.0
- CVE-2026-71362Adobe Commerce | Incorrect Authorization (CWE-863)9.1
- CVE-2026-47984Adobe Commerce | Incorrect Authorization (CWE-863)8.2
- CVE-2026-47997Adobe Commerce | Incorrect Authorization (CWE-863)5.9
- CVE-2026-47988Adobe Commerce | Incorrect Authorization (CWE-863)8.6
- CVE-2026-47999Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)4.8
- CVE-2026-48358Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)9.1
Product normalization is registry-driven with AI assist and human review. How it works