Magento Community-Edition vulnerabilities
355 known vulnerabilities affecting magento/community-edition.
Total CVEs
355
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL41HIGH105MEDIUM192LOW17
Vulnerabilities
Page 14 of 18
CVE-2019-7927MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7927 [MEDIUM] CWE-79 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to edit product content pages to inject malicious javascript.
ghsaosv
CVE-2019-7935MEDIUM≥ 2.1, < 2.1.18≥ 2.2, < 2.2.9+1 more2022-05-24
CVE-2019-7935 [MEDIUM] CWE-79 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content page titles to inject malicious javascript.
ghsaosv
CVE-2019-7852MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7852 [MEDIUM] CWE-200 Magento 2 Community Edition Path Disclosure
Magento 2 Community Edition Path Disclosure
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin panel, disclosing its location to potentially unauthorized parties.
ghsaosv
CVE-2019-8147MEDIUM≥ 2.2.0, < 2.2.10≥ 2.3.0, < 2.3.2-p12022-05-24
CVE-2019-8147 [MEDIUM] CWE-79 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via customer attribute label.
ghsaosv
CVE-2021-36037MEDIUM≥ 2.4.2-p1, < 2.4.2-p2≥ 0, < 2.3.7-p12022-05-24
CVE-2021-36037 [MEDIUM] CWE-285 Magento is affected by an improper authorization vulnerability
Magento is affected by an improper authorization vulnerability
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
ghsaosv
CVE-2019-7855MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7855 [MEDIUM] CWE-338 Magento 2 Community Cryptographic Flaw
Magento 2 Community Cryptographic Flaw
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.
ghsaosv
CVE-2019-7921MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7921 [MEDIUM] CWE-79 Magento 2 Community Edition Cross-site Scripting Vulnerability
Magento 2 Community Edition Cross-site Scripting Vulnerability
A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the product catalog to inject malicious javascript.
ghsaosv
CVE-2021-28584MEDIUM≥ 2.4.0, < 2.4.2-p1≥ 0, < 2.3.72022-05-24
CVE-2021-28584 [MEDIUM] CWE-22 Magento Path Traversal vulnerability
Magento Path Traversal vulnerability
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2019-7904MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7904 [MEDIUM] Magento 2 Community Edition Insufficient Access Controls
Magento 2 Community Edition Insufficient Access Controls
Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable a low-privileged user to make unauthorized environment configuration changes.
ghsaosv
CVE-2019-7862MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7862 [MEDIUM] CWE-79 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
ghsaosv
CVE-2019-7936MEDIUM≥ 2.3.0, < 2.3.2≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7936 [MEDIUM] CWE-79 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content block titles to inject malicious javascript.
ghsaosv
CVE-2019-7880MEDIUM≥ 2.1, < 2.1.18≥ 2.2, < 2.2.9+1 more2022-05-24
CVE-2019-7880 [MEDIUM] CWE-79 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to marketing email templates to inject malicious javascript.
ghsaosv
CVE-2019-7874MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7874 [MEDIUM] CWE-352 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of user roles.
ghsaosv
CVE-2019-8113MEDIUM≥ 2.2.0, < 2.2.10≥ 2.3.0, < 2.3.2-p12022-05-24
CVE-2019-8113 [MEDIUM] CWE-338 Magento 2 Community Weak PRNG
Magento 2 Community Weak PRNG
Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code for customer registration.
ghsaosv
CVE-2019-7929MEDIUM≥ 2.1.0, < 2.1.18≥ 2.2.0, < 2.2.9+1 more2022-05-24
CVE-2019-7929 [MEDIUM] CWE-200 Magento 2 Community Edition Information Disclosure
Magento 2 Community Edition Information Disclosure
An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges may be able to view metadata of a trusted device used by another administrator via a crafted http request.
ghsaosv
CVE-2019-8140MEDIUM≥ 2.2.0, < 2.2.10≥ 2.3.0, < 2.3.32022-05-24
CVE-2019-8140 [MEDIUM] CWE-434 Magento Unrestricted file upload vulnerability
Magento Unrestricted file upload vulnerability
An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to transform uploaded JPEG file into a PHP file.
ghsaosv
CVE-2021-21029MEDIUM≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.22022-05-24
CVE-2021-21029 [MEDIUM] CWE-79 Magento Reflected Cross-site Scripting vulnerability via 'file' parameter
Magento Reflected Cross-site Scripting vulnerability via 'file' parameter
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful e
ghsaosv
CVE-2021-39864MEDIUM≥ 2.4.2-p1, ≤ 2.4.2-p2≥ 0, < 2.3.7-p22022-05-24
CVE-2021-39864 [MEDIUM] CWE-352 Magento Open Source allows Cross-Site Request Forgery (CSRF)
Magento Open Source allows Cross-Site Request Forgery (CSRF)
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to a customer's cart by an unauthenticated attacker. Access to the admin console is not required f
ghsaosv
CVE-2019-8138MEDIUM≥ 2.2.0, < 2.2.10≥ 2.3.0, < 2.3.2-p12022-05-24
CVE-2019-8138 [MEDIUM] CWE-79 Magento 2 Community Edition XSS Vulnerability
Magento 2 Community Edition XSS Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.
ghsaosv
CVE-2019-7863MEDIUM≥ 2.1, < 2.1.18≥ 2.2, < 2.2.9+1 more2022-05-24
CVE-2019-7863 [MEDIUM] CWE-79 Magento Stored cross-site scripting in admin panel
Magento Stored cross-site scripting in admin panel
A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to products and categories.
ghsaosv