Composer package intelligence

magento/community-edition Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Composer package magento/community-edition, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
3
Known exploited vulnerabilities affecting magento/community-edition
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
magento/community-edition KEVs with sensor-observed exploitation activity

Review magento/community-edition exploitation against the versions you run

All three exploited magento/community-edition vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested magento/community-edition vulnerabilities

3 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2025-54236

Adobe Commerce | Improper Input Validation (CWE-20)

In CISA 01 Jun 2026
CVE-2022-24086

Adobe Commerce checkout improper input validation leads to remote code execution

In CISA 15 Feb 2022
CVE-2024-34102

XXE can expose crypt key and other secrets granting full admin access

In CISA 17 Jul 2024

Recurring weakness patterns

Improper Input Validation and Improper Restriction of XML External Entity Reference account for mapped occurrences across this magento/community-edition KEV portfolio.

Browse all KEVs →