Latest Security Updates

View All →
Security Research

CVE-2025-60991 (HIGH) CVSS 8.8

🟠 Severity: HIGH (CVSS 8.8)

A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user’s browser via a crafted payload injected into the cat parameter.

Published: 2025-10-01
Last …

Security Research

CVE-2025-27400 (LOW) CVSS 2.9

🟢 Severity: LOW (CVSS 2.9)

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Versions prior to 20.12.3 and 20.13.0 contain a vulnerability that allows …

Security Research

CVE-2026-34625 (MEDIUM) CVSS 5.4

🟡 Severity: MEDIUM (CVSS 5.4)

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the …

Security Research

CVE-2026-34624 (MEDIUM) CVSS 5.4

🟡 Severity: MEDIUM (CVSS 5.4)

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the …

Security Research

CVE-2026-34623 (MEDIUM) CVSS 5.4

🟡 Severity: MEDIUM (CVSS 5.4)

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the …