Magento Vulnerabilities & CVEs
The actively-exploited Magento/Adobe Commerce CVEs — CosmicSting, SessionReaper, TrojanOrders — affected versions, fixes and how to check your store.
Vulnerable WordPress Plugins: How They Get You Hacked (and Fixes)
Plugins cause most WordPress hacks. How plugin vulnerabilities are exploited, how to audit what you run, and how to reduce your attack surface.
Read article →TrojanOrders (CVE-2022-24086): The Checkout RCE Still Hitting Magento
TrojanOrders (CVE-2022-24086) abuses the Magento checkout to achieve RCE. How the attack works, who's still vulnerable, and how to detect and fix it.
Read article →SessionReaper (CVE-2025-54236): Unauthenticated RCE in Magento
SessionReaper (CVE-2025-54236, APSB25-94) is an unauthenticated RCE / account-takeover bug in Magento. Affected versions, the exact fixed patch per branch, and how to check.
Read article →Anatomy of a Magento Hack: CosmicSting → Card Skimmer → ClickFix
A real June 2026 Magento incident: how an EOL store was breached via CosmicSting (CVE-2024-34102), planted with a card decryptor, credential harvester, reverse shell and a ClickFix fake-CAPTCHA — who's impacted, which patch fixes it, and how to clean and secure your store.
Read article →CosmicSting (CVE-2024-34102): The Magento XXE Bug Explained
CosmicSting (CVE-2024-34102) lets attackers steal your Magento encryption key and chain to RCE. Affected versions, the fix, and why you must rotate the key.
Read article →Magento Vulnerabilities You Can't Ignore in 2026 (CVE List)
The actively-exploited Magento/Adobe Commerce CVEs in 2026 — SessionReaper, CosmicSting, TrojanOrders — affected versions, fixed patch levels and how to check your store.
Read article →SessionReaper & CosmicSting: The Magento CVEs You Can't Ignore in 2026
SessionReaper and CosmicSting are critically exploited Magento vulnerabilities. Find out if your store is patched — and what to do if it isn’t.
Read article →