20 KiB
20 KiB
Magento Open Source
LAB ONLY|AUTHORIZED TARGETS ONLY| 自动生成索引
- 系统 ID:
magento-open-source - 分类:
ecommerce - 覆盖策略:
history-full - 总案例数:
89 - 近 30 天新增/更新:
0 - 重点 Markdown 案例数:
0 - 已实证(真实版本):
0 - 已实证(synthetic):
0 - 阻塞数:
0 - 待人工/缺浏览器证据:
89 - 最近渲染时间:
2026-04-02T09:18:51+00:00
目标约束
- 适用目标类型:
lab-local, lab-public, authorized-third-party - 是否允许公网验证:
yes, but ownership or authorization is required - 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
来源
officialMagento GitHub Advisories (mode=core)officialOSV Magento Open Source (mode=core)officialNVD Magento (keyword=Magento; mode=core)ecosystem-authoritySansec Research (mode=extension)
案例列表
| 标题 | 严重度 | 案例状态 | 实证状态 | 实证方式 | 来源置信度 | 更新时间 | 案例页 |
|---|---|---|---|---|---|---|---|
| CVE-2019-7885 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.997 |
- |
| CVE-2019-7882 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.893 |
- |
| CVE-2019-7881 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.783 |
- |
| CVE-2019-7880 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.670 |
- |
| CVE-2019-7877 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.560 |
- |
| CVE-2019-7876 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.450 |
- |
| CVE-2019-7875 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.337 |
- |
| CVE-2019-7874 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.227 |
- |
| CVE-2019-7873 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.113 |
- |
| CVE-2019-7872 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:54.003 |
- |
| CVE-2019-7871 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:53.883 |
- |
| CVE-2019-7869 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:53.650 |
- |
| CVE-2019-7868 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:53.527 |
- |
| CVE-2019-7867 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:53.407 |
- |
| CVE-2019-7866 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:53.287 |
- |
| CVE-2019-7865 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:53.163 |
- |
| CVE-2019-7864 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:53.043 |
- |
| CVE-2019-7863 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.933 |
- |
| CVE-2019-7862 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.820 |
- |
| CVE-2019-7861 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.697 |
- |
| CVE-2019-7860 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.580 |
- |
| CVE-2019-7859 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.463 |
- |
| CVE-2019-7858 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.343 |
- |
| CVE-2019-7857 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.230 |
- |
| CVE-2019-7855 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.113 |
- |
| CVE-2019-7854 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:52.000 |
- |
| CVE-2019-7853 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:51.883 |
- |
| CVE-2019-7852 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:51.770 |
- |
| CVE-2019-7851 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:51.660 |
- |
| CVE-2019-7849 | high |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:48:51.440 |
- |
| CVE-2019-7139 | critical |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:47:38.667 |
- |
| CVE-2018-5301 | medium |
triage |
triage-manual |
synthetic |
official |
2024-11-21T04:08:32.663 |
- |
| CVE-2016-10704 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-20T01:37:25.860 |
- |
| CVE-2015-8707 | critical |
triage |
triage-manual |
synthetic |
official |
2025-04-20T01:37:25.860 |
- |
| CVE-2014-9758 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-20T01:37:25.860 |
- |
| CVE-2017-13761 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-20T01:37:25.860 |
- |
| CVE-2016-6485 | high |
triage |
triage-manual |
synthetic |
official |
2025-04-20T01:37:25.860 |
- |
| CVE-2016-4010 | critical |
triage |
triage-manual |
synthetic |
official |
2025-04-20T01:37:25.860 |
- |
| CVE-2016-2212 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2012-3243 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2015-3458 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2015-3457 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2015-1399 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2015-1398 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2015-1397 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2015-2068 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2015-2067 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2014-8770 | high |
triage |
triage-manual |
synthetic |
official |
2025-04-12T10:46:40.837 |
- |
| CVE-2011-5240 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-11T00:51:21.963 |
- |
| CVE-2009-0541 | medium |
triage |
triage-manual |
synthetic |
official |
2025-04-09T00:30:58.490 |
- |
| Surge in Magento 2 template attacks 2022-09-22 The critical template vulnerability in Magento 2 (CVE-2022-24086) is gaining popularity among eCommerce cyber criminals. The majority of recent Sansec forensic cases concern this attack method. In this article we share our findings of 3 template hacks, and hope it will help you if you are confron... skimming trojanorder | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| MagentoCore group hacks 7,339 stores and counting 2018-08-30 A single group is responsible for planting skimmers on 7339 individual stores in the last 6 months. The MagentoCore skimmer is now the most successful to date. Update 2018-09-07: Because Google Chrome has added the campaign to its blocklist last Saturday, the skimmers are now rapidly replacing &q... skimming MagentoCore skimmer | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Wiki | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Competing digital skimmers sabotage each other 2018-11-20 Skimmers found to subtly sabotage each others fraud operations. Competition is grim in the online skimming business (aka "MageCart"). The aggressive MagentoCore skimmer was previously observed to kick contending parasites from its victim hosts. But this week, we discovered that the bat... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Case Study: How eCommerce Hackers Silently Steal Credit Card Data 2021-05-03 The majority of online stores have never been hacked and, as a result, take a somewhat lax approach to cybersecurity. However, no less than 20% of all online stores get hacked every year, which means it might only be a matter of time until yours becomes the next victim. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Magento wish list exploit bypasses WAF protection 2023-12-18 Found your Magento 2 store hacked recently? Chances are, that attackers injected a malicious wish list. Just before Christmas? Oh the irony. skimming trojanorder | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Magento Security Release APSB25-08 [Impact Analysis] 2025-02-12 Critical (CVSS 9.4) release enables attackers to take control of customer accounts. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Bad extensions now main source of Magento hacks: a solution! 2019-01-29 In October last year I discovered several Magento extension 0days. As it turns out, this was only the tip of the iceberg: today, insecure 3rd party extensions are used to hack into thousands of stores. A group of Magento professionals have identified 63 vulnerable extensions, and are now releasin... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Magento and the Log4j vulnerability 2021-12-13 Updated Dec 20th. This article describes how Magento is affected by the critical log4j vulnerability, and what you can (and should) do to prevent a hack. A critical vulnerability in the popular Log4j Java library has been massively exploited since December 1st. It exposes full control to a remote... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Persistent Magento backdoor hidden in XML 2024-04-04 Does your Interceptor.php keep getting infected? Attackers are using a new method for malware persistence on Magento servers. Sansec discovered a cleverly crafted layout template in the database, which was used to automatically inject malware. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Persistent parasite in EOL Magento 2 2020-12-02 Over the last months, hackers have quietly added a subtle security flaw to over 50 large online stores, only to exploit them right before Black Friday, Sansec research shows. The flaw's presence would ensure future access for the attackers, even if their primary operation was blown. Sansec has be... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Policy | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Magento security extentions vendor got hacked 2019-10-07 The store of a US Magento extension vendor was found compromised. Attackers had write access to the server selling extensions. We are awaiting a statement on the integrity of downloaded software. Our malware crawlers detected a compromise of Extendware, a vendor of Magento extensions such as &quo... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Magento PolyShell: unrestricted file upload in Magento and Adobe Commerce 2026-03-17 A new vulnerability in the Magento and Adobe Commerce REST API allows attackers to upload executable files to any store. Adobe fixed the issue in a pre-release version but has not backported the patch. Many stores run web server configurations that enable either remote code execution (RCE) or acc... skimming magento adobe-commerce rce +3 | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| magento2 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Sign up | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Vendors defeat Magento security patch (+ simple check) 2023-01-17 Magento and Adobe Commerce stores around the world have been hammered with Trojan Order attacks this winter. And even if you have patched or installed Adobeâs 2.4.4 release, you may still be vulnerable. Sansec discovered that several vendors and agencies are actively bypassing this security fix, ... skimming trojanorder | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Warning: fake Magento patch 9789 contains virus 2017-04-21 Update May 21st: a similar phishing mail circulates about a fake patch SUPEE-1798. Update Apr 22nd: added reference to Neutrino Bot and POS systems This week a mail was sent out to announce the new Magento patch SUPEE-9789. It is fake and it contains malware. There is no patch 9789. The message... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| An OpenCart/Magento hacking dashboard 2017-04-07 This post shows how sophisticated Magento hacking operations have become nowadays. While investigating a bruteforced Magento store, we noticed that the hacker logged in using a curious referrer site: "GET /rss/catalog/notifystock/ HTTP/1.1" 200 5676 "http://194.87.232.147:777/"... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Pull requests | |||||||
| 804 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| SessionReaper attacks have started, 3 in 5 stores still vulnerable 2025-10-22 Six weeks after Adobe's emergency patch, SessionReaper (CVE-2025-54236) has entered active exploitation. Sansec Shield blocked dozens of attacks today. With only 38% of stores patched and exploit details now public, mass abuse will follow in the coming hours. skimming CVE-2025-54236 magento adobe-commerce +6 | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Claude finds 353 zero-days on Packagist 2026-01-22 We built an AI-powered security pipeline to audit popular ecommerce extensions on Packagist. The vulnerabilities we found range from password leaks to full remote code execution. skimming magento adobe-commerce supply-chain +1 | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| magento | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| CosmicSting attack threatens 75% of Adobe Commerce stores 2024-06-18 One week after the release of a critical security fix, just a quarter of all Adobe Commerce and Magento stores has been patched. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025-54236) 2025-09-08 SessionReaper (CVE-2025-54236) is a critical bug in Magento & Adobe Commerce. The bug may hand full control of a store to unauthenticated attackers. Automated attacks have hit over 50% of all stores globally. Merchants should act immediately. skimming CVE-2025-54236 magento adobe-commerce +5 | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| CosmicSting attack & defense overview 2024-09-16 CosmicSting (aka CVE-2024-34102) is the worst bug to hit Magento and Adobe Commerce stores in two years. Sansec observes that stores are getting hacked at a rate of 5 to 30 per hour. Merchants need to implement these counter measures as soon as possible. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Thousands of Adobe Commerce stores hacked in competing CosmicSting campaigns 2024-10-01 Cybercriminals have hacked 5% of all Adobe Commerce and Magento stores this summer. Among the victims are large international brands. Seven distinct groups are using CosmicSting attacks to plant malicious code on victim stores. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Adobe patches critical Magento admin takeover via menu injection 2025-06-12 A new attack on Adobe Commerce may break the menu bar for admin users. If your menu bar is missing, someone is stealing your session via CVE-2025-47110. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Notifications | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Fake Klaviyo accounts added to Magento 2022-12-21 Are your Magento admin accounts legitimate? Chances are, that a klaviyo_support_XXXX account was added this week. Best to quickly remove it and read this article. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Do these two things to keep your Magento 1 store running after June 2020-05-28 Over a 100 thousands Magento 1 stores will be running after Adobe terminates support in June (end-of-life). Many merchants need more time to transition to Magento 2 or another platform. No need to panic, your store will not suddenly crash on July 1st. But you should make two important arrangement... skimming magento 1 deadline | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Extortion of Magento merchants 2022-11-07 Sansec has received reports of criminals trying to extort Magento merchants with the message below. As long as the sender does not produce evidence, they almost certainly did not steal your sensitive data. Ignoring them is best. skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Projects | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Security | |||||||
| 0 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Critical Magento 2 flaw exploited within 16 hours 2019-05-10 The number of hacked Magento 2 stores spiked in the last four weeks, after a critical security flaw was discovered in March and criminals stole admin passwords within 16 hours. Merchants are advised to implement emergency measures, even if they had already patched. Update June 12th: While there w... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| A Magento breach analysis: part 1 2017-04-12 Part of a series where Magento security professionals share their case notes, so that we can ultimately distill a set of best practices, tools and workflow. Part of the job of running the MageReport service is that I get to investigate tons of hacked stores. About 50-200 new stores get hacked pe... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Cardbleed: 3% of Magento install base hacked 2020-09-14 Update Sept 18: Cardbleed has infected 2806 Magento1 stores so far (3% of total install base) Over the weekend, almost two thousand Magento 1 stores across the world have been hacked in the largest documented campaign to date. It was a typical Magecart attack: injected malicious code would inter... skimming | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |
| Issues | |||||||
| 1.2k | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Adobe Commerce merchants to be hit with TrojanOrders this season 2022-11-15 At least seven Magecart groups are injecting TrojanOrders at approximately 38% of Magento and Adobe Commerce websites in November. skimming trojanorder | unknown |
triage |
triage-manual |
synthetic |
ecosystem-authority |
`` | - |