magento

380 tracked vulnerabilities.

CVE-2020-3718 CRITICAL
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - RCE
Jan 29, 2020
CVSS 9.8
EPSS 0.09
CVE-2020-3717 MEDIUM
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - Path Traversal
Jan 29, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-3716 CRITICAL
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - Code Injection
Jan 29, 2020
CVSS 9.8
EPSS 0.17
CVE-2020-3715 MEDIUM
Magento <2.3.3, <2.2.10, <1.14.4.3, <1.9.4.3 - XSS
Jan 29, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-8158 CRITICAL
Magento <2.2.10, 2.3.<3, 2.3.2-p1 - XPath Injection
Nov 06, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-8157 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Downloadable Link Error Handling
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8156 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Server-Side Request Forgery via Connector API Endpoint
Nov 06, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8145 MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated Stored Cross-Site Scripting in Attribute Set Name
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8132 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting in Email Template Name Field
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8233 MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Unauthenticated Stored Cross-Site Scripting via HTML Comment Bypass
Nov 06, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-8232 MEDIUM
Magento < 1.9.4.3, < 1.14.4.3, 2.2.0-2.2.9, < 2.3.3 - Remote Code Execution via Import Race Condition
Nov 06, 2019
CVSS 6.6
EPSS 0.00
CVE-2019-8231 HIGH
Magento <1.14.4.3 - Authenticated RCE
Nov 06, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-8230 HIGH
Magentoprior <1.9.4.3-1.14.4.3 - Authenticated RCE
Nov 06, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-8229 HIGH
Magento <1.9.4.3-1.14.4.3 - Authenticated RCE
Nov 06, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-8228 MEDIUM
Magento < 1.9.4.3 and < 1.14.4.3 - Authenticated Stored Cross-Site Scripting in Email Template Editor
Nov 06, 2019
CVSS 4.8
EPSS 0.02
CVE-2019-8227 MEDIUM
Magento < 1.9.4.3 and < 1.14.4.3 - Authenticated Stored Cross-Site Scripting via Import/Export Profile Action XML
Nov 06, 2019
CVSS 4.8
EPSS 0.02
CVE-2019-8159 HIGH
Magento 2.2-2.2.9 and 2.3-2.3.2 - Authenticated Remote Code Execution via Arbitrary File Deletion
Nov 06, 2019
CVSS 8.8
EPSS 0.02
CVE-2019-8155 HIGH
Magento 1.5.0.0-1.9.4.2 and 1.9.0.0-1.14.4.2 - Cross-Site Request Forgery via CSRF Token in URL
Nov 06, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8154 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Product Design Update XML File
Nov 06, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8153 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Stored Cross-Site Scripting via escapeURL() Bypass
Nov 06, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-8152 MEDIUM
Magento 1.5.0.0-1.9.4.2, 1.9.0.0-1.14.4.2, 2.2.0-2.2.9, 2.3.0-2.3.2 - Stored XSS via WYSIWYG Editor
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8151 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via SSRF in Carrier Gateway
Nov 06, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8150 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Page Layout Manipulation
Nov 06, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8149 CRITICAL
Magento 2.2-2.2.9 and 2.3-2.3.2 - Insecure Session Management
Nov 06, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-8148 MEDIUM
Magento 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Page Builder
Nov 06, 2019
CVSS 4.8
EPSS 0.02