Magento

Magento is an Open Source ecommerce web application launched on March 31 2008. It was created by Varien building on components of the Zend Framework.

Official Site:

https://magento.com/

Severity Summary:

Critical: 33 High: 70 Medium: 116 Low: 4
Reference
Title
Severity
Magento Improper Access Control Vulnerability
Medium
Magento Improper Authorization Vulnerability
Medium
Magento Cross-Site Request Forgery (CSRF) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Insufficient Session Expiration Vulnerability
Medium
Magento Permissions Privileges and Access Controls Vulnerability
Medium
Magento Insufficient Session Expiration Vulnerability
Medium
Magento Improper Authentication Vulnerability
Medium
Magento Improper Control of Generation of Code (Code Injection) Vulnerability
Medium
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Input Validation Vulnerability
Medium
Magento Incorrect Authorization Vulnerability
Medium
Magento Improper Authorization Vulnerability
Medium
Magento Improper Authorization Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Authorization Vulnerability
Medium
Magento Violation of Secure Design Principles Vulnerability
Medium
Magento Improper Authorization Vulnerability
Medium
Magento Cross-Site Request Forgery (CSRF) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Incorrect Authorization Vulnerability
Medium
Magento Authorization Bypass Through User-Controlled Key Vulnerability
Medium
Magento Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Magento Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
Magento Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium