Package impact
Packagist / magento/project-community-edition
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2016-6485 | high | 7.5 | 7.5 | 9y ago | Unauthenticated crypto and weak IV in Magento\Framework\Encryption | |
| CVE-2025-54265 | medium | 5.9 | 5.9 | 8mo ago | Magento allows incorrect authorization |