home.social

#magento — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #magento, aggregated by home.social.

  1. 502 bad gateway in magento , docker exec -it magento-php netstat -tulnp | grep 9000 not showing anything #docker #nginx #localhost #magento

    askubuntu.com/q/1566773/612

  2. GPSR Magento Onlineshop Erweiterung von KonVis – GPSR (General Product Safety Regulation) Produktsicherheitsverordnung – EU-Verordnung: Ab 13. Dezember 2024 Infos zu Hersteller auf Produktseite anzeigen #beratung #eu-verordnung #magento #magento-2 konvis.de/neuigkeiten/magento/

  3. GPSR Magento Onlineshop Erweiterung von KonVis – GPSR (General Product Safety Regulation) Produktsicherheitsverordnung – EU-Verordnung: Ab 13. Dezember 2024 Infos zu Hersteller auf Produktseite anzeigen #beratung #eu-verordnung #magento #magento-2 konvis.de/neuigkeiten/magento/

  4. Is your Magento website crashing during traffic spikes? High traffic should mean higher sales — not downtime and lost revenue. Learn why Magento stores fail under pressure and how to fix performance issues with proper optimization, hosting, caching, and scalability strategies. Don’t let server overload hurt your brand reputation and conversions.
    Read More now : exinent.com/magento-website-cr
    #Exinent #Magento #Magento2 #eCommerce #WebsitePerformance #TrafficSpikes #OnlineStore #WebDevelopment

  5. Is your Magento store protected from downtime?
    Routine maintenance keeps your store secure, fast, and running smoothly.
    ✔ Security patches
    ✔ Performance optimization
    ✔ Extension updates
    ✔ Backup monitoring
    Don't wait until your website crashes. Learn More: exinent.com/magento-developmen
    #Magento #MagentoMaintenance #Ecommerce #WebsiteMaintenance #OnlineStore

  6. Discover why so many Magento stores lose sales due to poor optimization — from slow page loads and complicated checkout flows to weak mobile performance and SEO gaps. Learn how speed, user experience, hosting, and proper configuration directly impact conversions and revenue, and what you can do to fix them. Read the full blog now and boost your eCommerce success!
    Read full blog here : exinent.com/why-magento-stores
    #Exinent #Magento #eCommerce #Optimization #SalesGrowth #WebPerformance

  7. #SSI #Magento
    La faille d'Adobe Magento (devenu "Adobe Commerce") permet de téléverser du code à distance, ouvrir des backdoors..., et corrompre les SI des sociétés.
    L'impact potentiel est massif : 80% des sites utilisant la plateforme d'Adobe seraient impactés (au moins jusqu'à la version 2.4.9-alpha2), et elle a son propre nom : PolyShell.
    sansec.io/research/magento-pol

    À ce jour, il ne semble pas y avoir de correctif en production puisque la dernière maj date du 10 mars :
    helpx.adobe.com/fr/security/se

  8. #RGPD #SSI #Magento
    La fuite de Magento (relatée ce jour), la plateforme d’e-commerce d’Adobe, pourrait engendrer la compromission des données des clients de plus de 7 500 sites (d’après Wikipedia, 250 000 commerçants l’utiliseraient dans le monde !). Parmi eux, je cite : "Toyota, Fiat, Asus, Bandai, FedEx ainsi que divers organismes publics, universités et associations". On en saura peut être plus dans les semaines à venir : cyberattaque.org/magento-7-500

  9. Today in "I fucked up".

    A gal vibe coded her store, and she forgot to set the payment plugin to "production".

    She literally lost six figures (CLP) in a single day. She only noticed when called me:

    «Hey Italo, how do you remove the "Testing mode" when you pay?».

    Some people must stay AWAY from a computer, at least for a while.

    #VibeCoding #Programming #Coding #Code #Fail #SoftwareDevelopment #Shopify #WooCommerce #Instacart #Magento #PrestaShop #JumpSeller

  10. Today in "I fucked up".

    A gal vibe coded her store, and she forgot to set the payment plugin to "production".

    She literally lost six figures (CLP) in a single day. She only noticed when called me:

    «Hey Italo, how do you remove the "Testing mode" when you pay?».

    Some people must stay AWAY from a computer, at least for a while.

    #VibeCoding #Programming #Coding #Code #Fail #SoftwareDevelopment #Shopify #WooCommerce #Instacart #Magento #PrestaShop #JumpSeller

  11. Today in "I fucked up".

    A gal vibe coded her store, and she forgot to set the payment plugin to "production".

    She literally lost six figures (CLP) in a single day. She only noticed when called me:

    «Hey Italo, how do you remove the "Testing mode" when you pay?».

    Some people must stay AWAY from a computer, at least for a while.

    #VibeCoding #Programming #Coding #Code #Fail #SoftwareDevelopment #Shopify #WooCommerce #Instacart #Magento #PrestaShop #JumpSeller

  12. Today in "I fucked up".

    A gal vibe coded her store, and she forgot to set the payment plugin to "production".

    She literally lost six figures (CLP) in a single day. She only noticed when called me:

    «Hey Italo, how do you remove the "Testing mode" when you pay?».

    Some people must stay AWAY from a computer, at least for a while.

    #VibeCoding #Programming #Coding #Code #Fail #SoftwareDevelopment #Shopify #WooCommerce #Instacart #Magento #PrestaShop #JumpSeller

  13. Today in "I fucked up".

    A gal vibe coded her store, and she forgot to set the payment plugin to "production".

    She literally lost six figures (CLP) in a single day. She only noticed when called me:

    «Hey Italo, how do you remove the "Testing mode" when you pay?».

    Some people must stay AWAY from a computer, at least for a while.

    #VibeCoding #Programming #Coding #Code #Fail #SoftwareDevelopment #Shopify #WooCommerce #Instacart #Magento #PrestaShop #JumpSeller

  14. Vulnerability in REST API allows attackers to upload executable files.

    Unrestricted file upload: all #Magento #OpenSource and #AdobeCommerce versions up to 2.4.9-alpha2

    #XSS: all versions pre-2.3.5 or custom webserver config

    #RCE via #PHP upload: #nginx 2.0.0–2.2.x (via index.php filename), any non-stock version nginx passing all .php to fastcgi, #Apache pre-2.3.5 without php_flag engine 0

    Patched: 2.4.9-alpha3+ (pre-release only)

    bleepingcomputer.com/news/secu

    sansec.io/research/magento-pol

    #Magento2

  15. Модульный монолит против микросервисов: прагматизм вместо хайпа

    ​От моды к здравому смыслу: почему архитектура перестала слушать маркетинг и начала считать

    1. Введение: Эпоха «религиозной» архитектуры

    Примерно в 2015 году в индустрии разработки программного обеспечения...

    #DST #DSTGlobal #ДСТ #ДСТГлобал #DSTplatform #ДСТПлатформ #Модульныймонолит #микросервисы #прагматизм #CMS #CMF #хайп #разработка #Magento #PHP #Архитектура #Laravel #Symfony #Drupal

    Источник: dstglobal.ru/club/1153-modulny

  16. Ey, #Wikipedia… Warum machst Du es mir so schwer?
    Mein aktueller Account ist 15 Jahre alt. Ich habe gerade einmal 139 Bearbeitungen, weil ich meine Wiki-Aktivitäten einfach auf das Kiel WIki und die SPD Geschichtswerkstatt verlagert habe, weil sowieso mindestens jede zweite Änderung von irgendwem eingestampft wird.
    Ich hatte damals bspw. den EIntrag für #Magento angelegt. Gelöscht wegen Irrelevanz.
    Ich mach fast gar nichts mehr in der WIkipedia. Neulich habe ich einem User geholfen in seinem Userspace einen Eintrag für die #OSBA anzulegen. Auch habe aber auch den Eintrag zu meiner alten Schule ergänzt und die Mitarbeiterzahl beim HVV, n Foto von Franzi Kühne ergänzt…

    Jetzt bekomme ich eine Aufforderung offenzulegen, ob ich da ein Marketing- oder PR-Konto betreibe…!? Wirr. :think_bread:

  17. ⚠️ "Six semaines après le correctif d’urgence d’Adobe pour #SessionReaper (CVE-2025-54236), la vulnérabilité est entrée dans une phase d’exploitation active."

    ➡️ Selon Sansec Seuls 38 % des sites #Magento sont à jour — 3 sur 5 restent vulnérables à une exécution de code à distance

    Détails techniques et timeline complète sur le blog de Sansec.
    👇
    sansec.io/research/sessionreap

    Article FR
    👇
    infosec.pub/post/36573308

    Analyse technique / dff du patch
    👇
    slcyber.io/assetnote-security-

    Détails (G)CVE
    👇
    cve.circl.lu/vuln/CVE-2025-542

    #CyberVeille #CVE_2025_54236

  18. Should you find yourself in the unfortunate position of running (or being otherwise responsible for) a Magento / Adobe Commerce platform...you may wanna update _today_

    sansec.io/research/sessionreap

    TL;DR CVE-2025-54236: possible unauthenticated RCE and customer account takeover

    #magento #adobe #SessionReaper

  19. PHP: Вечный спор. Почему его ругают, но на нем до сих пор пишут?

    В мире технологий, где языки и фреймворки сходят со сцены, не успев получить признания, PHP демонстрирует феноменальную устойчивость. Это один из самых парадоксальных феноменов в индустрии: язык...

    #DST #DSTGlobal #ДСТ #ДСТГлобал #языкпрограммирования #DSTplatform #ДСТПлатформ #Laravel #Go #Rust #CMS #MODX #DiafanCMS #Magento #CSCart #OpenCart #CMF #Framework #Drupal #ORM #Symfony #Yii

    Читать далее: dstglobal.ru/club/1105-php-vec

  20. We ❤️ great people building apps that empower other folks to use our tools! The new open‑source #Magento module – from @jesperingels and the team at Bluebird Day – lets you integrate our real user monitoring into your Magento project in minutes – no coding required!

    Discover the benefits of gathering real user data, plus how to get started: speedcurve.com/blog/real-user-

    #webperf #ux #corewebvitals #sitespeed #pagespeed

  21. When Easypara one of France's largest online pharmacies, needed to migrate its infrastructure to a new PaaS provider, it couldn't afford disruption.

    With Platform.sh and Agence Dn'D, Easypara built a flexible and fault-tolerant infrastructure quickly without rearchitecting their apps. Discover how they achieved a seamless migration with zero downtime and a better developer workflow → bit.ly/easypara-case-study

    #ecommerce #magento #migration #businesstransformation #businesssuccess #casestudy

  22. 🚨 New Perspective on #Magento #XXE Vulnerability! 🚨

    Most write-ups cover the basic arbitrary file read vector. We’ve taken it further to demonstrate how CVE-2024-34102 can be chained to impersonate an admin user! 🔐

    github.com/redwaysecurity/CVEs

    #CyberSecurity #InfoSec

  23. Why you should care about the exploitation of CVE-2024-20720:
    A similar Adobe Commerce and Magento Open Source vulnerability CVE-2022-24086 (9.8 critical, disclosed 13 February 2024 by Adobe as a zero-day; improper input validation) was "exploited in the wild in very limited attacks targeting Adobe Commerce merchants." CVE-2022-24086 was added to CISA's KEV Catalog on 15 February 2024, so there is a strong possibility that they would consider CVE-2024-20720. 🔗 helpx.adobe.com/security/produ

    #CVE_2024_20720 #Adobe #Commerce #Magento #eitw #activeexploitation #threatintel #IOC

  24. Sansec reports active exploitation of CVE-2024-20720 (9.1 critical, disclosed 13 February 2024 by Adobe; Adobe Commerce/Magento Open Source OS command injection) to inject a fake Stripe payment skimmer, which would copy payment data to a compromised Magento store. IOC provided. 🔗 sansec.io/research/magento-xml

    #CVE_2024_20720 #Adobe #Commerce #Magento #eitw #threatintel #activeexploitation #IOC