Magento

Magento

222 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 36.43%
  • Veröffentlicht 10.04.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 04:47:38

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to ...

  • EPSS 0.03%
  • Veröffentlicht 08.01.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:32

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.

  • EPSS 0.1%
  • Veröffentlicht 30.12.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.

  • EPSS 0.2%
  • Veröffentlicht 26.09.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the refer...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 20.09.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

Exploit
  • EPSS 87.06%
  • Veröffentlicht 23.01.2017 21:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 15.04.2016 14:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition before 1.14.2.3 and Magento Community Edition before 1.9.2.3 allows remote attackers to obtain sensitive o...

Exploit
  • EPSS 2.15%
  • Veröffentlicht 29.04.2015 22:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not restrict the stream wrapper used in a template path, which allows remote administrators to inclu...

  • EPSS 8.96%
  • Veröffentlicht 29.04.2015 22:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

Exploit
  • EPSS 3.82%
  • Veröffentlicht 29.04.2015 22:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary PHP code via...