magento
380 tracked vulnerabilities.
CVE-2020-3718
CRITICAL
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - RCE
Jan 29, 2020
CVSS 9.8
EPSS 0.09
CVE-2020-3717
MEDIUM
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - Path Traversal
Jan 29, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-3716
CRITICAL
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - Code Injection
Jan 29, 2020
CVSS 9.8
EPSS 0.17
CVE-2020-3715
MEDIUM
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - XSS
Jan 29, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-8158
CRITICAL
Magento <2.2.10, 2.3.<3, 2.3.2-p1 - XPath Injection
Nov 06, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-8157
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Downloadable Link Error Handling
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8156
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Server-Side Request Forgery via Connector API Endpoint
Nov 06, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8145
MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated Stored Cross-Site Scripting in Attribute Set Name
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8132
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting in Email Template Name Field
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8233
MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Unauthenticated Stored Cross-Site Scripting via HTML Comment Bypass
Nov 06, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-8232
MEDIUM
Magento < 1.9.4.3, < 1.14.4.3, 2.2.0-2.2.9, < 2.3.3 - Remote Code Execution via Import Race Condition
Nov 06, 2019
CVSS 6.6
EPSS 0.00
CVE-2019-8231
HIGH
Magento <1.14.4.3 - Authenticated RCE
Nov 06, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-8230
HIGH
Magentoprior <1.9.4.3-1.14.4.3 - Authenticated RCE
Nov 06, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-8229
HIGH
Magento <1.9.4.3-1.14.4.3 - Authenticated RCE
Nov 06, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-8228
MEDIUM
Magento < 1.9.4.3 and < 1.14.4.3 - Authenticated Stored Cross-Site Scripting in Email Template Editor
Nov 06, 2019
CVSS 4.8
EPSS 0.02
CVE-2019-8227
MEDIUM
Magento < 1.9.4.3 and < 1.14.4.3 - Authenticated Stored Cross-Site Scripting via Import/Export Profile Action XML
Nov 06, 2019
CVSS 4.8
EPSS 0.02
CVE-2019-8159
HIGH
Magento 2.2-2.2.9 and 2.3-2.3.2 - Authenticated Remote Code Execution via Arbitrary File Deletion
Nov 06, 2019
CVSS 8.8
EPSS 0.02
CVE-2019-8155
HIGH
Magento 1.5.0.0-1.9.4.2 and 1.9.0.0-1.14.4.2 - Cross-Site Request Forgery via CSRF Token in URL
Nov 06, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8154
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Product Design Update XML File
Nov 06, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8153
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Stored Cross-Site Scripting via escapeURL() Bypass
Nov 06, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-8152
MEDIUM
Magento 1.5.0.0-1.9.4.2, 1.9.0.0-1.14.4.2, 2.2.0-2.2.9, 2.3.0-2.3.2 - Stored XSS via WYSIWYG Editor
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8151
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via SSRF in Carrier Gateway
Nov 06, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8150
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Page Layout Manipulation
Nov 06, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8149
CRITICAL
Magento 2.2-2.2.9 and 2.3-2.3.2 - Insecure Session Management
Nov 06, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-8148
MEDIUM
Magento 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Page Builder
Nov 06, 2019
CVSS 4.8
EPSS 0.02