Adobe Magento Open Source vulnerabilities
32 known vulnerabilities affecting adobe/magento_open_source.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH17MEDIUM14
Vulnerabilities
Page 1 of 2
CVE-2022-24093HIGHCVSS 7.2fixed in 2.3.7≥ 2.4.0, < 2.4.3+2 more2023-09-12
CVE-2022-24093 [CRITICAL] CWE-20 CVE-2022-24093: Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an imprope
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
nvd
CVE-2023-22247HIGHCVSS 7.5fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22247 [HIGH] CWE-91 CVE-2023-22247: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Inj
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-22249MEDIUMCVSS 4.8fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22249 [MEDIUM] CWE-79 CVE-2023-22249: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored C
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the v
nvd
CVE-2023-22251MEDIUMCVSS 4.3fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22251 [MEDIUM] CWE-863 CVE-2023-22251: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorre
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
nvd
CVE-2023-22250MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+1 more2023-03-27
CVE-2023-22250 [MEDIUM] CWE-284 CVE-2023-22250: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Imprope
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
nvd
CVE-2022-35698MEDIUMCVSS 5.4fixed in 2.4.4v2.4.4+1 more2022-10-14
CVE-2022-35698 [CRITICAL] CWE-79 CVE-2022-35698: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cros
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
nvd
CVE-2022-35689MEDIUMCVSS 5.3fixed in 2.4.4v2.4.4+1 more2022-10-14
CVE-2022-35689 [MEDIUM] CWE-284 CVE-2022-35689: Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper A
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
nvd
CVE-2021-39864MEDIUMCVSS 6.5≤ 2.3.7v2.3.7+2 more2021-10-15
CVE-2021-39864 [MEDIUM] CWE-352 CVE-2021-39864: Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are af
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for success
nvd
CVE-2021-36020CRITICALCVSS 9.8≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36020 [HIGH] CWE-91 CVE-2021-36020: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.
nvd
CVE-2021-36024HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36024 [CRITICAL] CWE-78 CVE-2021-36024: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
nvd
CVE-2021-36029HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36029 [CRITICAL] CWE-285 CVE-2021-36029: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
nvd
CVE-2021-36028HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36028 [CRITICAL] CWE-91 CVE-2021-36028: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
nvd
CVE-2021-36030HIGHCVSS 7.5≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36030 [HIGH] CWE-20 CVE-2021-36030: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.
nvd
CVE-2021-36041HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36041 [CRITICAL] CWE-20 CVE-2021-36041: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could upload a specially crafted file in the 'pub/media` directory could lead to remote code execution.
nvd
CVE-2021-36022HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36022 [CRITICAL] CWE-78 CVE-2021-36022: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
nvd
CVE-2021-36033HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36033 [CRITICAL] CWE-91 CVE-2021-36033: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
nvd
CVE-2021-36032HIGHCVSS 8.8≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36032 [HIGH] CWE-20 CVE-2021-36032: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.
nvd
CVE-2021-36031HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36031 [HIGH] CWE-22 CVE-2021-36031: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a Path Traversal vulnerability via the `theme[preview_image]` parameter. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
nvd
CVE-2021-36025HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36025 [CRITICAL] CWE-20 CVE-2021-36025: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges can leverage this vulnerability to achieve remote code execution.
nvd
CVE-2021-36034HIGHCVSS 7.2≥ 2.3.0, ≤ 2.3.7≥ 2.4.0, ≤ 2.4.2+1 more2021-09-01
CVE-2021-36034 [CRITICAL] CWE-20 CVE-2021-36034: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are af
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.
nvd
1 / 2Next →