magento

380 tracked vulnerabilities.

CVE-2019-7940 MEDIUM
Magento < 1.9.4.2, < 1.14.4.2, 2.1 < 2.1.18, 2.2 < 2.2.9, 2.3 < 2.3.2 - Stored XSS via Store Currency
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7939 MEDIUM
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Reflected Cross-Site Scripting on Customer Cart Checkout Page
Aug 02, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-7938 MEDIUM
Magento < 1.9.4.2, < 1.14.4.2, 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Stored XSS in Catalog Price Rules
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7937 MEDIUM
Magento 2.1.0-2.1.17 - Authenticated Stored Cross-Site Scripting in Admin Panel Product Attributes
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7936 MEDIUM
Magento 2.1.0-2.1.17 and 2.3.0-2.3.1 - Authenticated Stored Cross-Site Scripting in Admin Panel Content Block Titles
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7935 MEDIUM
Magento < 1.9.4.2, < 1.14.4.2, 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Stored XSS in Admin Panel
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7934 MEDIUM
Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - XSS
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7932 HIGH
Magento <1.9.4.2-2.3.2 - Authenticated RCE
Aug 02, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-7930 HIGH
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Authenticated Arbitrary File Upload via Import Configuration Bypass
Aug 02, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-7929 MEDIUM
Magento <2.1.18-2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-7928 HIGH
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Unauthenticated Denial of Service via PayPal Token Exchange
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7927 MEDIUM
Magento 2.1.0-2.1.17 - Authenticated Stored Cross-Site Scripting in Admin Panel
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7926 MEDIUM
Magento 2.1.0-2.1.17 - Authenticated Stored Cross-Site Scripting in Admin Panel
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7925 MEDIUM
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Insecure Direct Object Reference
Aug 02, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-7923 HIGH
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Authenticated Server-Side Request Forgery in Shipment Settings
Aug 02, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-7921 MEDIUM
Magento 2.1.0-2.1.17 - Authenticated Stored Cross-Site Scripting in Product Catalog Form
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-7915 HIGH
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Unauthenticated Denial of Service via Full Page Cache Manipulation
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7913 HIGH
Magento 2.1.0-2.1.17 - Authenticated Server-Side Request Forgery via Shipment Method Manipulation
Aug 02, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-7912 HIGH
Magento <2.1.18-2.3.2 - Auth Bypass
Aug 02, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-7911 HIGH
Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - SSRF
Aug 02, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-7909 MEDIUM
Magento < 1.9.4.2, < 1.14.4.2, 2.1.0-2.1.17 - Authenticated Stored Cross-Site Scripting in Email Templates
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7908 MEDIUM
Magento 2.1.0-2.1.17 - Authenticated Stored Cross-Site Scripting in Admin Panel
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7904 MEDIUM
Magento <2.1.18, <2.2.9, <2.3.2 - Privilege Escalation
Aug 02, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-7903 HIGH
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Authenticated Remote Code Execution via Email Template Preview
Aug 02, 2019
CVSS 7.2
EPSS 0.01
CVE-2019-7899 MEDIUM
Magento Open Source <1.9.4.2 - Info Disclosure
Aug 02, 2019
CVSS 5.3
EPSS 0.00