Skip to main content

Vendor archive

magento CVEs

Beta · best-effort

224 CVEs tagged to vendor magento32 Critical, 70 High, 118 Medium, 4 Low, 0 Unrated.

CVE-2019-7861

Published Aug 2, 2019

Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7860

Published Aug 2, 2019

A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7859

Published Aug 2, 2019

A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7858

Published Aug 2, 2019

A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information with an algorithm that…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7857

Published Aug 2, 2019

A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7855

Published Aug 2, 2019

A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7854

Published Aug 2, 2019

An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7853

Published Aug 2, 2019

A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authentica…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7852

Published Aug 2, 2019

A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7851

Published Aug 2, 2019

A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from custome…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7849

Published Aug 2, 2019

A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7139

Published Apr 10, 2019

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5301

Published Jan 8, 2018

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10704

Published Dec 30, 2017

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8707

Published Sep 26, 2017

Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9758

Published Sep 20, 2017

Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6485

Published Mar 1, 2017

The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4010

Published Jan 23, 2017

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2016-2212

Published Apr 15, 2016

The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition before 1.14.2.3 and Magento Communi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3458

Published Apr 29, 2015

The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not restrict the stream wrapp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3457

Published Apr 29, 2015

Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1399

Published Apr 29, 2015

PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE)…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2015-1398

Published Apr 29, 2015

Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users to include and execute…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2015-1397

Published Apr 29, 2015

SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 201-224 of 224 CVEsPage 9 of 9