cbcvebase.

Adobe Magento Commerce vulnerabilities

81 known vulnerabilities affecting adobe/magento_commerce.

Total CVEs
81
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH24MEDIUM44LOW4

Vulnerabilities

Page 2 of 5
CVE-2021-21029P4MEDIUMCVSS 4.8≥ unspecified, ≤ 2.4.12021-02-11
CVE-2021-21029 [MEDIUM] CWE-79 CVE-2021-21029: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.
nvd
CVE-2021-21013P3HIGHCVSS 8.1≥ unspecified, ≤ 2.4.12021-01-13
CVE-2021-21013 [HIGH] CWE-863 CVE-2021-21013: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and update arbitrary information on another user's account.
nvd
CVE-2021-36031P3HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36031 [HIGH] CWE-22 CVE-2021-36031: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a Path Traversal vulnerability via the `theme[preview_image]` parameter. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
nvd
CVE-2021-36030P3HIGHCVSS 7.5≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36030 [HIGH] CWE-20 CVE-2021-36030: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.
nvd
CVE-2021-36024P3HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36024 [HIGH] CWE-78 CVE-2021-36024: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
nvd
CVE-2021-36041P3HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36041 [HIGH] CWE-20 CVE-2021-36041: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could upload a specially crafted file in the 'pub/media` directory could lead to remote code execution.
nvd
CVE-2021-36029P3HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36029 [HIGH] CWE-285 CVE-2021-36029: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
nvd
CVE-2022-34258P3MEDIUMCVSS 4.8≥ unspecified, ≤ 2.4.42022-08-16
CVE-2022-34258 [MEDIUM] CWE-79 CVE-2022-34258: Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are a Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse
nvd
CVE-2021-21015P3HIGHCVSS 8.0≥ unspecified, ≤ 2.4.12021-02-11
CVE-2021-21015 [HIGH] CWE-78 CVE-2021-21015: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
nvd
CVE-2021-28584P3HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28584 [HIGH] CWE-22 CVE-2021-28584: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.
nvd
CVE-2023-22247P3HIGHCVSS 7.5≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22247 [HIGH] CWE-91 CVE-2023-22247: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Inj Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-22248P3HIGHCVSS 7.5≥ unspecified, ≤ 2.4.62023-06-15
CVE-2023-22248 [HIGH] CWE-863 CVE-2023-22248: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are a Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to leak another user's data. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-22249P3MEDIUMCVSS 4.8≥ unspecified, ≤ 2.4.5-p12023-03-27
CVE-2023-22249 [MEDIUM] CWE-79 CVE-2023-22249: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored C Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the v
nvd
CVE-2021-36044P3HIGHCVSS 7.5≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36044 [HIGH] CWE-20 CVE-2021-36044: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.
nvd
CVE-2021-21030P3HIGHCVSS 8.1≥ unspecified, ≤ 2.4.12021-02-11
CVE-2021-21030 [HIGH] CWE-79 CVE-2021-21030: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.
nvd
CVE-2021-36043P3MEDIUMCVSS 6.6≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36043 [MEDIUM] CWE-918 CVE-2021-36043: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.
nvd
CVE-2020-24400P3HIGHCVSS 7.1≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24400 [HIGH] CWE-89 CVE-2020-24400: Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that c Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.
nvd
CVE-2020-24401P3MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24401 [MEDIUM] CWE-863 CVE-2020-24401: Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerab Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.
nvd
CVE-2023-38209P3MEDIUMCVSS 6.5≤ 2.4.4-p42023-08-09
CVE-2023-38209 [MEDIUM] CWE-863 CVE-2023-38209: Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) ar Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerability that could lead to a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
nvd
CVE-2021-28563P3MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28563 [MEDIUM] CWE-285 CVE-2021-28563: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticated attacker. Access to the admin console is required for successful exp
nvd
Adobe Magento Commerce vulnerabilities | cvebase