magento

380 tracked vulnerabilities.

CVE-2019-8147 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Customer Attribute Label
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8146 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Customer Attribute
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8144 CRITICAL
Magento 2.3 < 2.3.3 and 2.3.2 < 2.3.2-p1 - Unauthenticated Remote Code Execution via PageBuilder Template Methods
Nov 06, 2019
CVSS 9.8
EPSS 0.03
CVE-2019-8143 MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated SQL Injection via Email Templates
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8142 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Order Title
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8141 HIGH
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, <2.3.3 - Remote Code Execution via Phar Deserialization
Nov 06, 2019
CVSS 7.2
EPSS 0.02
CVE-2019-8140 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Unrestricted File Upload via Media File Storage Synchronization
Nov 06, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-8139 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.1 - Authenticated Stored Cross-Site Scripting in Page Builder Dynamic Block
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8138 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Sale Pickup Event API Endpoint
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8137 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Custom Layout Update
Nov 06, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8136 CRITICAL
Magento <2.2.10-2.3.3/2.3.2-p1 - Info Disclosure
Nov 06, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-8135 CRITICAL
Magento 2.2-2.2.9 and 2.3-2.3.2 - Remote Code Execution via Symfony Dependency Injection
Nov 06, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-8134 HIGH
Magento 2.2-2.2.9 and 2.3-2.3.2 - Authenticated SQL Injection via Email Template Variables
Nov 06, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-8133 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Security Bypass and Denial of Service via Sitemap Generation
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8131 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting in Inventory Source Code Field
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8130 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated SQL Injection via Email Template Database Connection
Nov 06, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-8129 MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated Stored Cross-Site Scripting via Translation Injection
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8128 MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Website Name
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8127 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated SQL Injection via Newsletter Template Editing
Nov 05, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-8126 MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated XML External Entity Injection via XML Layout Processing
Nov 05, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-8125 HIGH
Magento 1.5.0.0-1.9.4.2 and 1.9.0.0-1.14.4.2 - Authenticated Remote Code Execution via Support Configuration
Nov 05, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8124 MEDIUM
Magento <2.1.19-2.3.3 - Info Disclosure
Nov 05, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-8123 MEDIUM
Magento <1.9.4.3-2.3.3 - Info Disclosure
Nov 05, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-8122 HIGH
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, 2.3.0-2.3.2 - Authenticated Remote Code Execution via Product Import Layout Update
Nov 05, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8121 CRITICAL
Magento <2.1.19-2.3.3 - Code Injection
Nov 05, 2019
CVSS 9.8
EPSS 0.00