magento
380 tracked vulnerabilities.
CVE-2019-8147
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Customer Attribute Label
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8146
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Customer Attribute
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8144
CRITICAL
Magento 2.3 < 2.3.3 and 2.3.2 < 2.3.2-p1 - Unauthenticated Remote Code Execution via PageBuilder Template Methods
Nov 06, 2019
CVSS 9.8
EPSS 0.03
CVE-2019-8143
MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated SQL Injection via Email Templates
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8142
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Order Title
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8141
HIGH
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, <2.3.3 - Remote Code Execution via Phar Deserialization
Nov 06, 2019
CVSS 7.2
EPSS 0.02
CVE-2019-8140
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Unrestricted File Upload via Media File Storage Synchronization
Nov 06, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-8139
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.1 - Authenticated Stored Cross-Site Scripting in Page Builder Dynamic Block
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8138
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Sale Pickup Event API Endpoint
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8137
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Custom Layout Update
Nov 06, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8136
CRITICAL
Magento <2.2.10-2.3.3/2.3.2-p1 - Info Disclosure
Nov 06, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-8135
CRITICAL
Magento 2.2-2.2.9 and 2.3-2.3.2 - Remote Code Execution via Symfony Dependency Injection
Nov 06, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-8134
HIGH
Magento 2.2-2.2.9 and 2.3-2.3.2 - Authenticated SQL Injection via Email Template Variables
Nov 06, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-8133
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Security Bypass and Denial of Service via Sitemap Generation
Nov 06, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8131
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting in Inventory Source Code Field
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8130
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated SQL Injection via Email Template Database Connection
Nov 06, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-8129
MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated Stored Cross-Site Scripting via Translation Injection
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8128
MEDIUM
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Website Name
Nov 06, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8127
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated SQL Injection via Newsletter Template Editing
Nov 05, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-8126
MEDIUM
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated XML External Entity Injection via XML Layout Processing
Nov 05, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-8125
HIGH
Magento 1.5.0.0-1.9.4.2 and 1.9.0.0-1.14.4.2 - Authenticated Remote Code Execution via Support Configuration
Nov 05, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8124
MEDIUM
Magento <2.1.19-2.3.3 - Info Disclosure
Nov 05, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-8123
MEDIUM
Magento <1.9.4.3-2.3.3 - Info Disclosure
Nov 05, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-8122
HIGH
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, 2.3.0-2.3.2 - Authenticated Remote Code Execution via Product Import Layout Update
Nov 05, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8121
CRITICAL
Magento <2.1.19-2.3.3 - Code Injection
Nov 05, 2019
CVSS 9.8
EPSS 0.00