Skip to content
MAGEKWIKScanner

Security research

Magento security blog

Technical breakdowns of what actually breaks Magento & Adobe Commerce stores — critical CVEs, card skimmers, and misconfigurations. Root cause, how attackers abuse it, real-world examples, and the exact fix. Sourced from the advisories and research, not marketing.

CRITICAL CVES CVE-2015-1397 CVSS 6.5 scan.magekwik.com
critical Critical CVEs

Shoplift (CVE-2015-1397): the Magento 1 SQL injection that was weaponised in 24 hours

CVE-2015-1397 is the SQL injection at the centre of the Magento 1 "Shoplift" chain — an unauthenticated grid-export flaw that let attackers write admin accounts straight into the database. Patched by SUPEE-5344 in February 2015, it was mass-exploited within a day of disclosure. The mechanism, the indicators of compromise, and the fix.

6 min read