← Back

Magento

magento

Vendor: Magentocommerce • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Magentocommerce
1Magento
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
1Magentocommerce
1Magento
Apr 29, 2026
Nov 6, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof S...Show more
Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less