Skip to main content

Vendor archive

magento CVEs

Beta · best-effort

224 CVEs tagged to vendor magento32 Critical, 70 High, 118 Medium, 4 Low, 0 Unrated.

CVE-2021-21026

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21025

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could l…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21024

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitat…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21023

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21022

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21020

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Succ…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21019

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21018

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation module. Successful exploita…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21016

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to r…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21015

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successf…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24407

Published Nov 9, 2020

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abu…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-24406

Published Nov 9, 2020

When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during buil…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24405

Published Nov 9, 2020

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authent…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24404

Published Nov 9, 2020

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by use…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24403

Published Nov 9, 2020

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by a…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24402

Published Nov 9, 2020

Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authent…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24401

Published Nov 9, 2020

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24400

Published Nov 9, 2020

Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be expl…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-24408

Published Oct 16, 2020

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. Thi…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-9692

Published Jul 29, 2020

Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9691

Published Jul 29, 2020

Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9690

Published Jul 29, 2020

Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification b…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9689

Published Jul 29, 2020

Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9665

Published Jul 22, 2020

Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 224 CVEsPage 2 of 9