Skip to main content

Vendor archive

magento CVEs

Beta · best-effort

224 CVEs tagged to vendor magento32 Critical, 70 High, 118 Medium, 4 Low, 0 Unrated.

CVE-2019-8158

Published Nov 6, 2019

An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rend…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-8157

Published Nov 6, 2019

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8156

Published Nov 6, 2019

A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to mo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8145

Published Nov 6, 2019

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8132

Published Nov 6, 2019

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8233

Published Nov 6, 2019

In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of the sanitization engine ignorin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8232

Published Nov 6, 2019

In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileg…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8231

Published Nov 6, 2019

In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8230

Published Nov 6, 2019

In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute arbitrary code through a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8229

Published Nov 6, 2019

In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through craf…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8228

Published Nov 6, 2019

in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional ema…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8227

Published Nov 6, 2019

In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export fu…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8159

Published Nov 6, 2019

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8155

Published Nov 6, 2019

Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8154

Published Nov 6, 2019

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8153

Published Nov 6, 2019

A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerabil…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8152

Published Nov 6, 2019

A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An aut…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8151

Published Nov 6, 2019

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to manipulate ship…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8150

Published Nov 6, 2019

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate layouts an…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8149

Published Nov 6, 2019

Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-8148

Published Nov 6, 2019

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8147

Published Nov 6, 2019

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8146

Published Nov 6, 2019

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8144

Published Nov 6, 2019

A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-8143

Published Nov 6, 2019

A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send maliciou…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 224 CVEsPage 4 of 9