Skip to main content

Vendor archive

magento CVEs

Beta · best-effort

224 CVEs tagged to vendor magento32 Critical, 70 High, 118 Medium, 4 Low, 0 Unrated.

CVE-2021-36036

Published Sep 6, 2023

Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36023

Published Sep 6, 2023

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attac…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36021

Published Sep 6, 2023

Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled updat…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42344

Published Oct 20, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34259

Published Aug 16, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Secu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34258

Published Aug 16, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abus…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34257

Published Aug 16, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abus…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34256

Published Aug 16, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privile…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34255

Published Aug 16, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34254

Published Aug 16, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Pat…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34253

Published Aug 16, 2022

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker wi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28567

Published Sep 8, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successf…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28566

Published Sep 8, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png fil…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-28585

Published Jun 28, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New customer WebAPI.Succe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28584

Published Jun 28, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Succe…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28583

Published Jun 28, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28563

Published Jun 28, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28556

Published Jun 28, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Su…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21014

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21032

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of this issue could lead t…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21031

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21030

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature.…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21029

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successfu…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21027

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Success…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 224 CVEsPage 1 of 9