Adobe Magento Commerce vulnerabilities
85 known vulnerabilities affecting adobe/magento_commerce.
Total CVEs
85
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH25MEDIUM44LOW4
Vulnerabilities
Page 5 of 5
CVE-2020-24405MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24405 [MEDIUM] CWE-285 CVE-2020-24405: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulne
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.
cvelistv5nvd
CVE-2020-24403LOWCVSS 2.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24403 [LOW] CWE-285 CVE-2020-24403: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulner
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
cvelistv5nvd
CVE-2020-24406LOWCVSS 3.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24406 [LOW] CWE-200 CVE-2020-24406: When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an informati
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attackers if they are able to identify other exploitable vulnerabilities in the environment.
cvelistv5nvd
CVE-2020-24404LOWCVSS 2.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24404 [LOW] CWE-285 CVE-2020-24404: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerabili
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
cvelistv5nvd
CVE-2020-24408MEDIUMCVSS 6.1≥ unspecified, ≤ 2.4.02020-10-16
CVE-2020-24408 [MEDIUM] CWE-79 CVE-2020-24408: Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uplo
cvelistv5nvd
← Previous5 / 5