Magento Community-Edition vulnerabilities
355 known vulnerabilities affecting magento/community-edition.
Total CVEs
355
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL41HIGH105MEDIUM192LOW17
Vulnerabilities
Page 8 of 18
CVE-2022-34259MEDIUM≥ 2.3.0, < 2.3.7-p4≥ 2.4.4, < 2.4.5+1 more2022-08-17
CVE-2022-34259 [MEDIUM] CWE-284 Magento Improper Access Control vulnerability
Magento Improper Access Control vulnerability
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
ghsaosv
CVE-2022-34257MEDIUM≥ 2.3.0, < 2.3.7-p4≥ 2.4.4, < 2.4.5+1 more2022-08-17
CVE-2022-34257 [MEDIUM] CWE-79 Magento stored Cross-Site Scripting (XSS) vulnerability
Magento stored Cross-Site Scripting (XSS) vulnerability
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the
ghsaosv
CVE-2022-34258MEDIUM≥ 2.3.0, < 2.3.7-p4≥ 2.4.4, < 2.4.5+1 more2022-08-17
CVE-2022-34258 [MEDIUM] CWE-79 Magento stored Cross-Site Scripting (XSS) vulnerability
Magento stored Cross-Site Scripting (XSS) vulnerability
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to t
ghsaosv
CVE-2019-8149CRITICAL≥ 2.2, < 2.2.10≥ 2.3, < 2.3.2-p12022-05-24
CVE-2019-8149 [CRITICAL] CWE-287 Magento Broken authentication and session managememt
Magento Broken authentication and session managememt
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.
ghsaosv
CVE-2020-9631CRITICAL≥ 2.3.0, < 2.3.4-p2≥ 0, ≤ 2.2.112022-05-24
CVE-2020-9631 [CRITICAL] Magento security mitigation bypass vulnerability
Magento security mitigation bypass vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-21014CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.22022-05-24
CVE-2021-21014 [CRITICAL] CWE-434 Magento vulnerable to a file upload restriction bypass
Magento vulnerable to a file upload restriction bypass
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2021-21024CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.1-p12022-05-24
CVE-2021-21024 [CRITICAL] CWE-89 Magento Blind SQL Injection in the Search module
Magento Blind SQL Injection in the Search module
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2020-9578CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9578 [CRITICAL] CWE-78 Magento command injection vulnerability
Magento command injection vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-36040CRITICAL≥ 2.4.2-p1, < 2.4.2-p2≥ 0, < 2.3.7-p12022-05-24
CVE-2021-36040 [CRITICAL] CWE-20 Magento has a file extension restrictions bypass
Magento has a file extension restrictions bypass
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to remote code execution.
ghsaosv
CVE-2020-9691CRITICAL≥ 0, < 2.3.5-p22022-05-24
CVE-2020-9691 [CRITICAL] CWE-79 Magento DOM-based Cross-site scripting vulnerability
Magento DOM-based Cross-site scripting vulnerability
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2020-9630CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9630 [CRITICAL] CWE-269 Magento business logic error vulnerability
Magento business logic error vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.
ghsaosv
CVE-2021-21019CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.1-p12022-05-24
CVE-2021-21019 [CRITICAL] CWE-91 Magento XML injection in the Widgets module
Magento XML injection in the Widgets module
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2021-21016CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.22022-05-24
CVE-2021-21016 [CRITICAL] CWE-78 Magento OS command injection via the WebAPI
Magento OS command injection via the WebAPI
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2020-9576CRITICAL≥ 2.3.0, < 2.3.4-p2≥ 0, < 2.2.122022-05-24
CVE-2020-9576 [CRITICAL] CWE-78 Magento command injection vulnerability
Magento command injection vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2020-9632CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9632 [CRITICAL] Magento security mitigation bypass vulnerability
Magento security mitigation bypass vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-36028CRITICAL≥ 0, < 2.3.7-p1≥ 2.4.2-p1, < 2.4.2-p22022-05-24
CVE-2021-36028 [CRITICAL] CWE-91 Magento has an XML Injection vulnerability
Magento has an XML Injection vulnerability
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
ghsaosv
CVE-2021-36025CRITICAL≥ 0, < 2.3.7-p1≥ 2.4.2-p1, < 2.4.2-p22022-05-24
CVE-2021-36025 [CRITICAL] CWE-20 Magento is affected by an improper input validation vulnerability while saving a customer's details
Magento is affected by an improper input validation vulnerability while saving a customer's details
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges
ghsaosv
CVE-2020-9580CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9580 [CRITICAL] Magento Security mitigation bypass vulnerability
Magento Security mitigation bypass vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2020-9583CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9583 [CRITICAL] CWE-78 Magento command injection vulnerability
Magento command injection vulnerability
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-36042CRITICAL≥ 2.4.2-p1, < 2.4.2-p2≥ 0, < 2.3.7-p12022-05-24
CVE-2021-36042 [CRITICAL] CWE-20 Magento executes code via the API File Option Upload Extension
Magento executes code via the API File Option Upload Extension
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestricted file upload which can result in remote code execution.
ghsaosv