Adobe Magento vulnerabilities
190 known vulnerabilities affecting adobe/magento.
Total CVEs
190
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL22HIGH64MEDIUM91LOW13
Vulnerabilities
Page 10 of 10
CVE-2020-9584MEDIUMCVSS 5.4v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9584 [MEDIUM] CWE-79 CVE-2020-9584: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2020-9581MEDIUMCVSS 6.1v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9581 [MEDIUM] CWE-79 CVE-2020-9581: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2020-8818HIGHCVSS 8.1v2.3.42020-02-25
CVE-2020-8818 [HIGH] CWE-346 CVE-2020-8818: An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin
An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order statu
nvd
CVE-2020-3716CRITICALCVSS 9.8v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3716 [CRITICAL] CWE-502 CVE-2020-3716: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2020-3718CRITICALCVSS 9.8v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3718 [CRITICAL] CVE-2020-3718: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2020-3719HIGHCVSS 7.5v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3719 [HIGH] CWE-89 CVE-2020-3719: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2020-3758MEDIUMCVSS 6.1v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3758 [MEDIUM] CWE-79 CVE-2020-3758: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2020-3715MEDIUMCVSS 6.1v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3715 [MEDIUM] CWE-79 CVE-2020-3715: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2020-3717MEDIUMCVSS 5.3v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3717 [MEDIUM] CWE-22 CVE-2020-3717: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-8235MEDIUMCVSS 6.5v2.3 prior to 2.3.1v2.2 prior to 2.2.8+1 more2019-10-30
CVE-2019-8235 [MEDIUM] CWE-639 CVE-2019-8235: An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 p
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personally identifiable shipping details of another user due to insufficient validation of user controlled input.
nvd
← Previous10 / 10