Critical XSS (Cross-Site Scripting) vulnerabilities have been found in both version 1 and 2 of Magento ecommerce platform. Each of them could be used to take over vulnerable ecommerce sites, putting the stores users and their credit card data at risk. Magento is running on about 1.3% of the top 10 million websites, making it the fourth most popular website CMS (Content Management System) and the only one in the top five thats a specialist ecommerce system.”]