Adobe Magento Commerce vulnerabilities

85 known vulnerabilities affecting adobe/magento_commerce.

Total CVEs
85
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH25MEDIUM44LOW4

Vulnerabilities

Page 3 of 5
CVE-2021-36025HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36025 [HIGH] CWE-20 CVE-2021-36025: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges can leverage this vulnerability to achieve remote code execution.
cvelistv5nvd
CVE-2021-36034HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36034 [HIGH] CWE-20 CVE-2021-36034: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
cvelistv5nvd
CVE-2021-36044HIGHCVSS 7.5≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36044 [HIGH] CWE-20 CVE-2021-36044: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.
cvelistv5nvd
CVE-2021-36031HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36031 [HIGH] CWE-22 CVE-2021-36031: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a Path Traversal vulnerability via the `theme[preview_image]` parameter. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
cvelistv5nvd
CVE-2021-36032HIGHCVSS 8.3≥ unspecified, ≤ 2.4.2≥ unspecified, ≤ 2.4.2-p1+2 more2021-09-01
CVE-2021-36032 [HIGH] CWE-20 Magento Commerce Improper Input Validation Could Lead To Information Exposure and Privilege Escalation Magento Commerce Improper Input Validation Could Lead To Information Exposure and Privilege Escalation Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to
cvelistv5
CVE-2021-36042HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36042 [HIGH] CWE-20 CVE-2021-36042: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestricted file upload which can result in remote code execution.
cvelistv5nvd
CVE-2021-36026MEDIUMCVSS 6.1≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36026 [MEDIUM] CWE-79 CVE-2021-36026: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when th
cvelistv5nvd
CVE-2021-36043MEDIUMCVSS 6.6≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36043 [MEDIUM] CWE-918 CVE-2021-36043: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.
cvelistv5nvd
CVE-2021-36027MEDIUMCVSS 6.1≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36027 [MEDIUM] CWE-79 CVE-2021-36027: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vu
cvelistv5nvd
CVE-2021-36012MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36012 [MEDIUM] CWE-840 CVE-2021-36012: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.
cvelistv5nvd
CVE-2021-36038MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36038 [MEDIUM] CWE-20 CVE-2021-36038: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the Multishipping Module. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
cvelistv5nvd
CVE-2021-36037MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36037 [MEDIUM] CWE-285 CVE-2021-36037: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
cvelistv5nvd
CVE-2021-36039MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.22021-09-01
CVE-2021-36039 [MEDIUM] CWE-863 CVE-2021-36039: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the `quoteId` parameter. An attacker can abuse this vulnerability to disclose sensitive information.
cvelistv5nvd
CVE-2021-28584HIGHCVSS 7.2≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28584 [HIGH] CWE-22 CVE-2021-28584: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.
cvelistv5nvd
CVE-2021-28556MEDIUMCVSS 4.8≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28556 [MEDIUM] CWE-79 CVE-2021-28556: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
cvelistv5nvd
CVE-2021-28563MEDIUMCVSS 6.5≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28563 [MEDIUM] CWE-285 CVE-2021-28563: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticated attacker. Access to the admin console is required for successful exp
cvelistv5nvd
CVE-2021-28583MEDIUMCVSS 4.2≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28583 [MEDIUM] CWE-657 CVE-2021-28583: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.
cvelistv5nvd
CVE-2021-28585MEDIUMCVSS 5.3≥ unspecified, ≤ 2.4.22021-06-28
CVE-2021-28585 [MEDIUM] CWE-20 CVE-2021-28585: Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New customer WebAPI.Successful exploitation could allow an attacker to send unsolicited spam e-mails.
cvelistv5nvd
CVE-2021-21064MEDIUMCVSS 4.9≥ unspecified, ≤ 1.1.42021-02-25
CVE-2021-21064 [MEDIUM] CWE-22 CVE-2021-21064: Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Mage Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote serv
cvelistv5nvd
CVE-2021-21025CRITICALCVSS 9.1≥ unspecified, ≤ 2.4.12021-02-11
CVE-2021-21025 [CRITICAL] CWE-91 CVE-2021-21025: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
cvelistv5nvd