Adobe Magento vulnerabilities

175 known vulnerabilities affecting adobe/magento.

Total CVEs
175
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL22HIGH55MEDIUM86LOW12

Vulnerabilities

Page 9 of 9
CVE-2020-9576CRITICALCVSS 9.8v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9576 [CRITICAL] CWE-77 CVE-2020-9576: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
cvelistv5nvd
CVE-2020-9588HIGHCVSS 7.2v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9588 [HIGH] CWE-203 CVE-2020-9588: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
cvelistv5nvd
CVE-2020-9591HIGHCVSS 7.5v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9591 [HIGH] CVE-2020-9591: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin panel.
cvelistv5nvd
CVE-2020-9587HIGHCVSS 7.5v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9587 [HIGH] CVE-2020-9587: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.
cvelistv5nvd
CVE-2020-9577MEDIUMCVSS 6.1v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9577 [MEDIUM] CWE-79 CVE-2020-9577: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure .
cvelistv5nvd
CVE-2020-9581MEDIUMCVSS 6.1v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9581 [MEDIUM] CWE-79 CVE-2020-9581: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
cvelistv5nvd
CVE-2020-9584MEDIUMCVSS 5.4v2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier versions2020-06-26
CVE-2020-9584 [MEDIUM] CWE-79 CVE-2020-9584: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
cvelistv5nvd
CVE-2020-8818HIGHCVSS 8.1v2.3.42020-02-25
CVE-2020-8818 [HIGH] CWE-346 CVE-2020-8818: An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order statu
nvd
CVE-2020-3716CRITICALCVSS 9.8v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3716 [CRITICAL] CWE-502 CVE-2020-3716: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
cvelistv5nvd
CVE-2020-3718CRITICALCVSS 9.8v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3718 [CRITICAL] CVE-2020-3718: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
cvelistv5nvd
CVE-2020-3719HIGHCVSS 7.5v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3719 [HIGH] CWE-89 CVE-2020-3719: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
cvelistv5nvd
CVE-2020-3758MEDIUMCVSS 6.1v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3758 [MEDIUM] CWE-79 CVE-2020-3758: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
cvelistv5nvd
CVE-2020-3715MEDIUMCVSS 6.1v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3715 [MEDIUM] CWE-79 CVE-2020-3715: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
cvelistv5nvd
CVE-2020-3717MEDIUMCVSS 5.3v2.3.3 and earlierv2.2.10 and earlier+2 more2020-01-29
CVE-2020-3717 [MEDIUM] CWE-22 CVE-2020-3717: Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlie Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
cvelistv5nvd
CVE-2019-8235MEDIUMCVSS 6.5v2.3 prior to 2.3.1v2.2 prior to 2.2.8+1 more2019-10-30
CVE-2019-8235 [MEDIUM] CWE-639 CVE-2019-8235: An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 p An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. An authenticated user may be able to view personally identifiable shipping details of another user due to insufficient validation of user controlled input.
cvelistv5nvd