magento

380 tracked vulnerabilities.

CVE-2019-8120 MEDIUM
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, 2.3.0-2.3.2 - Authenticated Stored Cross-Site Scripting via Customer Email Address
Nov 05, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8119 HIGH
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, 2.3.0-2.3.2 - Authenticated Remote Code Execution via XSLT File Injection
Nov 05, 2019
CVSS 7.2
EPSS 0.02
CVE-2019-8118 MEDIUM
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, 2.3.0-2.3.2 - Cleartext Storage of Sensitive Information
Nov 05, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-8117 MEDIUM
Magento 2.2.0-2.2.9 - Authenticated Stored Cross-Site Scripting via Product View ID
Nov 05, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8116 HIGH
Magento <2.2.10-2.3.3/2.3.2-p1 - Auth Bypass
Nov 05, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8115 MEDIUM
Magento 2.2.0-2.2.9 - Authenticated Reflected Cross-Site Scripting via Product Image Upload
Nov 05, 2019
CVSS 4.8
EPSS 0.02
CVE-2019-8114 HIGH
Magento < 1.9.4.3 and < 1.14.4.3 - Authenticated Remote Code Execution via Crafted Configuration Archive Upload
Nov 05, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8113 MEDIUM
Magento <2.2.10-2.3.3/2.3.2-p1 - Info Disclosure
Nov 05, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-8112 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Unauthenticated Security Bypass via Email Confirmation Mechanism
Nov 05, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-8111 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Email Template Plugin
Nov 05, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8110 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Email Template Interceptor Manipulation
Nov 05, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-8109 HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via CSRF
Nov 05, 2019
CVSS 8.0
EPSS 0.00
CVE-2019-8108 MEDIUM
Magento 2.2-2.2.9 and 2.3-2.3.2 - Authenticated Insecure Session Validation Manipulation
Nov 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8107 MEDIUM
Magento <2.2.10-2.3.3/2.3.2-p1 - Privilege Escalation
Nov 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8093 HIGH
Magento 2.2-2.2.10 and 2.3-2.3.3 - Authenticated Arbitrary File Access via Downloadable Products Upload Controller
Nov 05, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-8092 MEDIUM
Magento 2.2.0-2.2.9 - Authenticated Reflected Cross-Site Scripting via Email Template Preview
Nov 05, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-8091 HIGH
Magento 1.5.0.0-1.9.4.2 and 1.9.0.0-1.14.4.2 - Authenticated Remote Code Execution via Layout Updates
Nov 05, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-8090 MEDIUM
Magento <2.1.19-2.3.3 - Privilege Escalation
Nov 05, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-8235 MEDIUM
Magento 2.1.0-2.1.16, 2.2.0-2.2.7 - Authenticated Insecure Direct Object Reference
Oct 30, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-7951 HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7950 HIGH
Magento <2.1.18-2.3.2 - Auth Bypass
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7947 MEDIUM
Magento Open Source <1.9.4.2 - Magento Commerce <1.14.4.2 - Magento...
Aug 02, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-7945 MEDIUM
Magento Open Source <1.9.4.2 - Magento Commerce <1.14.4.2 - Magento...
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-7944 MEDIUM
Magento Open Source <1.9.4.2 - Magento Commerce <1.14.4.2 - Magento...
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-7942 HIGH
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Authenticated Remote Code Execution via XML Layout Updates
Aug 02, 2019
CVSS 7.2
EPSS 0.01