Magento Community-Edition vulnerabilities

355 known vulnerabilities affecting magento/community-edition.

Total CVEs
355
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL41HIGH105MEDIUM192LOW17

Vulnerabilities

Page 8 of 18
CVE-2022-34259MEDIUM≥ 2.3.0, < 2.3.7-p4≥ 2.4.4, < 2.4.5+1 more2022-08-17
CVE-2022-34259 [MEDIUM] CWE-284 Magento Improper Access Control vulnerability Magento Improper Access Control vulnerability Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
ghsaosv
CVE-2022-34257MEDIUM≥ 2.3.0, < 2.3.7-p4≥ 2.4.4, < 2.4.5+1 more2022-08-17
CVE-2022-34257 [MEDIUM] CWE-79 Magento stored Cross-Site Scripting (XSS) vulnerability Magento stored Cross-Site Scripting (XSS) vulnerability Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the
ghsaosv
CVE-2022-34258MEDIUM≥ 2.3.0, < 2.3.7-p4≥ 2.4.4, < 2.4.5+1 more2022-08-17
CVE-2022-34258 [MEDIUM] CWE-79 Magento stored Cross-Site Scripting (XSS) vulnerability Magento stored Cross-Site Scripting (XSS) vulnerability Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to t
ghsaosv
CVE-2019-8149CRITICAL≥ 2.2, < 2.2.10≥ 2.3, < 2.3.2-p12022-05-24
CVE-2019-8149 [CRITICAL] CWE-287 Magento Broken authentication and session managememt Magento Broken authentication and session managememt Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.
ghsaosv
CVE-2020-9631CRITICAL≥ 2.3.0, < 2.3.4-p2≥ 0, ≤ 2.2.112022-05-24
CVE-2020-9631 [CRITICAL] Magento security mitigation bypass vulnerability Magento security mitigation bypass vulnerability Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-21014CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.22022-05-24
CVE-2021-21014 [CRITICAL] CWE-434 Magento vulnerable to a file upload restriction bypass Magento vulnerable to a file upload restriction bypass Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2021-21024CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.1-p12022-05-24
CVE-2021-21024 [CRITICAL] CWE-89 Magento Blind SQL Injection in the Search module Magento Blind SQL Injection in the Search module Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2020-9578CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9578 [CRITICAL] CWE-78 Magento command injection vulnerability Magento command injection vulnerability Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-36040CRITICAL≥ 2.4.2-p1, < 2.4.2-p2≥ 0, < 2.3.7-p12022-05-24
CVE-2021-36040 [CRITICAL] CWE-20 Magento has a file extension restrictions bypass Magento has a file extension restrictions bypass Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to remote code execution.
ghsaosv
CVE-2020-9691CRITICAL≥ 0, < 2.3.5-p22022-05-24
CVE-2020-9691 [CRITICAL] CWE-79 Magento DOM-based Cross-site scripting vulnerability Magento DOM-based Cross-site scripting vulnerability Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2020-9630CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9630 [CRITICAL] CWE-269 Magento business logic error vulnerability Magento business logic error vulnerability Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.
ghsaosv
CVE-2021-21019CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.1-p12022-05-24
CVE-2021-21019 [CRITICAL] CWE-91 Magento XML injection in the Widgets module Magento XML injection in the Widgets module Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2021-21016CRITICAL≥ 0, < 2.3.6-p1≥ 2.4.0, < 2.4.22022-05-24
CVE-2021-21016 [CRITICAL] CWE-78 Magento OS command injection via the WebAPI Magento OS command injection via the WebAPI Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
ghsaosv
CVE-2020-9576CRITICAL≥ 2.3.0, < 2.3.4-p2≥ 0, < 2.2.122022-05-24
CVE-2020-9576 [CRITICAL] CWE-78 Magento command injection vulnerability Magento command injection vulnerability Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2020-9632CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9632 [CRITICAL] Magento security mitigation bypass vulnerability Magento security mitigation bypass vulnerability Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-36028CRITICAL≥ 0, < 2.3.7-p1≥ 2.4.2-p1, < 2.4.2-p22022-05-24
CVE-2021-36028 [CRITICAL] CWE-91 Magento has an XML Injection vulnerability Magento has an XML Injection vulnerability Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.
ghsaosv
CVE-2021-36025CRITICAL≥ 0, < 2.3.7-p1≥ 2.4.2-p1, < 2.4.2-p22022-05-24
CVE-2021-36025 [CRITICAL] CWE-20 Magento is affected by an improper input validation vulnerability while saving a customer's details Magento is affected by an improper input validation vulnerability while saving a customer's details Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges
ghsaosv
CVE-2020-9580CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9580 [CRITICAL] Magento Security mitigation bypass vulnerability Magento Security mitigation bypass vulnerability Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2020-9583CRITICAL≥ 0, ≤ 2.2.11≥ 2.3.0, < 2.3.4-p22022-05-24
CVE-2020-9583 [CRITICAL] CWE-78 Magento command injection vulnerability Magento command injection vulnerability Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ghsaosv
CVE-2021-36042CRITICAL≥ 2.4.2-p1, < 2.4.2-p2≥ 0, < 2.3.7-p12022-05-24
CVE-2021-36042 [CRITICAL] CWE-20 Magento executes code via the API File Option Upload Extension Magento executes code via the API File Option Upload Extension Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestricted file upload which can result in remote code execution.
ghsaosv
Magento Community-Edition vulnerabilities | cvebase