CVE-2016-4010: Magento
Critical severity, CVSS 9.8. EPSS: 92.9% chance of exploitation in the next 30 days.
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
Affected products
- Magento Magento: up to and including 2.0.5
Published 2017-01-23. Last modified 2026-06-17.