Composer package intelligence
magento/community-edition Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Composer package magento/community-edition, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting magento/community-edition
- In CISA KEV
- 3
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- magento/community-edition KEVs with sensor-observed exploitation activity
Review magento/community-edition exploitation against the versions you run
All three exploited magento/community-edition vulnerabilities tracked here are also listed in CISA KEV.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
Attested magento/community-edition vulnerabilities
3 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2025-54236
Adobe Commerce | Improper Input Validation (CWE-20) |
In CISA | 01 Jun 2026 |
|
CVE-2022-24086
Adobe Commerce checkout improper input validation leads to remote code execution |
In CISA | 15 Feb 2022 |
|
CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access |
In CISA | 17 Jul 2024 |
Recurring weakness patterns
Improper Input Validation and Improper Restriction of XML External Entity Reference account for mapped occurrences across this magento/community-edition KEV portfolio.