Adobe Magento Commerce vulnerabilities

85 known vulnerabilities affecting adobe/magento_commerce.

Total CVEs
85
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH25MEDIUM44LOW4

Vulnerabilities

Page 5 of 5
CVE-2020-24405MEDIUMCVSS 4.3≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24405 [MEDIUM] CWE-285 CVE-2020-24405: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulne Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.
cvelistv5nvd
CVE-2020-24403LOWCVSS 2.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24403 [LOW] CWE-285 CVE-2020-24403: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulner Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
cvelistv5nvd
CVE-2020-24406LOWCVSS 3.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24406 [LOW] CWE-200 CVE-2020-24406: When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an informati When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attackers if they are able to identify other exploitable vulnerabilities in the environment.
cvelistv5nvd
CVE-2020-24404LOWCVSS 2.7≥ unspecified, ≤ 2.4.02020-11-09
CVE-2020-24404 [LOW] CWE-285 CVE-2020-24404: Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerabili Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
cvelistv5nvd
CVE-2020-24408MEDIUMCVSS 6.1≥ unspecified, ≤ 2.4.02020-10-16
CVE-2020-24408 [MEDIUM] CWE-79 CVE-2020-24408: Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uplo
cvelistv5nvd