Skip to content
Threat Feed

Tag

Magento

3 briefs RSS
critical advisory

CVE-2026-53787: Unauthenticated Arbitrary File Upload in Amasty Order Attributes for Magento 2

An unauthenticated arbitrary file upload vulnerability in Amasty Order Attributes for Magento 2 (versions before 4.0.0) allows attackers to upload files of any type to the store's media directory, which can lead to remote code execution (RCE) on misconfigured servers by uploading PHP files, enable malware hosting, facilitate stored cross-site scripting (XSS) via HTML/SVG uploads, or achieve path traversal to write files outside the intended directory.

PoC Order Attributes for Magento 2 +2 web-vulnerability file-upload magento amasty rce xss
2r 4t 1c 1i updated
critical advisory

Mirasvit Full Page Cache Warmer for Magento 2 PHP Object Injection RCE (CVE-2026-45247)

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability (CVE-2026-45247) that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

Full Page Cache Warmer for Magento 2 +1 php-object-injection rce magento web-application cve-2026-45247
2r 2t 1c
critical advisory

Adobe Commerce XXE Vulnerability (CVE-2024-34102) Exploit Released

A public exploit, named CosmicSting, has been released for CVE-2024-34102, an XML External Entity (XXE) Injection vulnerability in Adobe Commerce allowing for unauthenticated remote file read, SSRF, and potential RCE.

Commerce cve-2024-34102 xxe adobe commerce magento
2r 1t 1c 1i