Magento

Magento is an Open Source ecommerce web application launched on March 31 2008. It was created by Varien building on components of the Zend Framework.

Official Site:

https://magento.com/

Severity Summary:

Critical: 33 High: 70 Medium: 116 Low: 4
Reference
Title
Severity
Magento Incorrect Authorization Vulnerability
High
Magento Vulnerability
High
Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Magento Deserialization of Untrusted Data Vulnerability
High
Magento Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability
High
Magento Improper Input Validation Vulnerability
High
Magento Vulnerability
High
Magento Insufficient Verification of Data Authenticity Vulnerability
High
Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Magento Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability
High
Magento Improper Access Control Vulnerability
High
Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Magento Vulnerability
High
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Cryptographic Issues Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Authorization Bypass Through User-Controlled Key Vulnerability
Medium
Magento Cross-Site Request Forgery (CSRF) Vulnerability
Medium
Magento Cross-Site Request Forgery (CSRF) Vulnerability
Medium
Magento Incorrect Authorization Vulnerability
Medium
Magento Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium