magento

380 tracked vulnerabilities.

CVE-2019-7865 HIGH
Magento 2.1-2.1.17 - Cross-Site Request Forgery in Checkout Cart Item
Aug 02, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-7864 MEDIUM
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Insecure Direct Object Reference in RSS Feeds
Aug 02, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-7863 MEDIUM
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Authenticated Stored Cross-Site Scripting in Admin Panel
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7862 MEDIUM
Magento 2.1.0-2.1.17 - Reflected Cross-Site Scripting in Product Widget Chooser
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7861 HIGH
Magento <2.1.18-2.3.2 - Auth Bypass
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7860 HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7859 HIGH
Magento <2.1.18-2.3.2 - Path Traversal
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7858 HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7857 MEDIUM
Magento 2.1.0-2.1.17, 2.2.0-2.2.8 - Cross-Site Request Forgery via Insufficient Anti-CSRF Token
Aug 02, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-7855 MEDIUM
Magento <2.1.18-2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-7854 HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7853 MEDIUM
Magento 2.1.0-2.1.17 - Authenticated Stored Cross-Site Scripting in Tax Notifications Configuration
Aug 02, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-7852 MEDIUM
Magento <2.1.18-2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-7851 MEDIUM
Magento 2.1.0-2.1.17 - Cross-Site Request Forgery
Aug 02, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-7849 HIGH
Magento <1.9.4.2, <1.14.4.2, <2.1.18, <2.2.9, <2.3.2 - Info Disclosure
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-7139 CRITICAL NUCLEI
Magento <2.1.18-2.3.2 - SQL Injection
Apr 10, 2019
CVSS 9.8
EPSS 0.60
CVE-2018-5301 MEDIUM
Magento < 2.0.10 and 2.1.x < 2.1.2 - Cross-Site Request Forgery
Jan 08, 2018
CVSS 6.5
EPSS 0.00
CVE-2016-10704 MEDIUM
Magento < 2.0.10 and 2.1.x < 2.1.2 - Cross-Site Scripting via Email Template Preview
Dec 30, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6485 HIGH
Magento 2 - Use of a Broken or Risky Cryptographic Algorithm in Framework/Encryption/Crypt.php
Mar 01, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-4010 CRITICAL
Magento < 2.0.6 - Unauthenticated PHP Object Injection via Serialized Shopping Cart Data
Jan 23, 2017
CVSS 9.8
EPSS 0.87
CVE-2016-2212 MEDIUM
Magento < 1.9.2.2 and < 1.14.2.2 - Exposure of Sensitive Order Information via RSS Feed Request
Apr 15, 2016
CVSS 5.3
EPSS 0.00
CVE-2015-6497 HIGH
Magento < 1.9.2.1 and < 1.14.2.1 - Authenticated Remote Code Execution via Product API
Jan 15, 2020
CVSS 8.8
EPSS 0.03
CVE-2015-8707 CRITICAL
Magento < 1.9.2.1 and < 1.14.2.1 - Exposure of Sensitive Information via Password Reset Token
Sep 26, 2017
CVSS 9.8
EPSS 0.00
CVE-2015-3458
Magento CE/EE <1.9.1.0-1.14.1.0 - Command Injection
Apr 29, 2015
EPSS 0.02
CVE-2015-3457
Magento CE/EE <1.9.1.0-1.14.1.0 - Auth Bypass
Apr 29, 2015
EPSS 0.09