depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/composer/magento/project-community-edition

magento/project-community-edition

composerv2.0.2

eCommerce Platform for Growth (Community Edition)

License OSL-3.0network copyleft53 versions2 deps
magento/magento2-community-edition
15
/ 100
Health
do not use

magento/project-community-edition has critical vulnerabilities — do not use

Update to >= 2.4.4-p12 to fix known vulnerabilities

  • Moderate health score (15/100) — verify manually
  • 45 high severity vulnerabilities
  • 15 critical vulnerabilities
Health breakdown0 – 100
0/25
maintenance
0/20
popularity
0/25
security
15/15
maturity
0/15
community
Vulnerabilities
146
15 critical45 high74 medium12 low
Advisories (146)
SeverityIDSummaryFixed in
highCVE-2023-22247Magento Open Source allows XML Injection2.4.4-p3
highCVE-2024-20719Magento Open Source allows Cross-Site Scripting (XSS)2.4.4-p7
criticalBIT-magento-2021-21014Magento vulnerable to a file upload restriction bypass2.4.2
highCVE-2025-54264Magento vulnerable to stored Cross-Site Scripting (XSS)2.4.6-p13
lowCVE-2023-29294Magento Open Source has Business Logic Errors Vulnerability2.4.4-p4
highCVE-2024-39402Magento OS Command ('OS Command Injection') vulnerability2.4.4-p10
mediumBIT-magento-2021-21020Magento Improper Access Control2.4.1-p1
criticalCVE-2021-36040Magento has a file extension restrictions bypass2.3.7-p1
lowCVE-2025-27192Magento does not properly protect credentials2.4.8-beta2
mediumCVE-2023-22251Magento Open Source allows Incorrect Authorization2.4.5-p2
lowCVE-2023-29295Magento Open Source allows Incorrect Authorization2.4.4-p4
highCVE-2025-24411Magento Improper Access Control vulnerability2.4.4-p12
highCVE-2021-36043Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension2.4.2-p2
mediumBIT-magento-2021-28556Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies2.3.7
lowBIT-magento-2020-24403Magento incorrect user permissions vulnerability within the Inventory component2.4.1
mediumCVE-2025-24408Magento Information Exposure vulnerability2.4.4-p12
mediumCVE-2021-36012Magento affected by a business logic error in the placeOrder graphql mutation2.4.2-p2
mediumCVE-2021-36039Magento discloses sensitive information2.4.2-p2
lowCVE-2023-38219Magento Open Source allows Cross-Site Scripting (XSS)2.4.4-p6
lowCVE-2023-29296Magento Open Source allows Incorrect Authorization2.4.4-p4
... and 126 more
Threat intelligence
1 actively exploited (CISA KEV)
Threat tier per vulnerability derived from CISA KEV catalog + FIRST.org EPSS scores.

Health History

Dependency Tree

License Audit

Dependencies (2)
magento/product-community-editioncomposer/composer
API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/composer/magento/project-community-edition

Last updated · 2016-01-28T23:14:06+00:00

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents