🚀 CloudSEK has raised $19M Series B1 Round – Powering the Future of Predictive Cybersecurity
Read more
Magento usage statistics from Builtwith
Usage by Country |
Usage by Ecommerce Category |
|||
Country |
Magento Instances |
|||
| India | 2,692 | Fashion | 5,047 | |
| United States | 82,477 | Shoes | 4,529 | |
| UK | 15,649 | Furniture | 2,535 | |
| Canada | 2,873 | Apparels | 2,399 | |
| Australia | 5,674 | Groceries and Food | 2,049 | |
| Germany | 13,303 | Jewellery | 1,802 | |
| Netherlands | 11,880 | Medicine | 1,735 | |
It is likely that threat actors are exploiting zero days and publicly disclosed vulnerabilities in Magento, to gain access to the ecommerce shops. Past campaigns have heavily relied on “shoplift bug CVE-2015-1397” to compromise the shops.
Vulnerability |
Description |
| CVE-2020-9576 | Remote Code Execution (RCE) |
| CVE-2020-9578 | Remote Code Execution (RCE) |
| CVE-2020-9582 | Remote Code Execution (RCE) |
| CVE-2020-9583 | Remote Code Execution (RCE) |
| CVE-2020-9579 | Remote Code Execution (RCE) |
| CVE-2020-9580 | Remote Code Execution (RCE) |
| CVE-2020-9689 | Path traversal leading to RCE |
| CVE-2020-9692 | Remote Code Execution (RCE) |
| CVE-2020-9690 | Signature verification bypass |






