- EPSS 17.34%
- Published 29.01.2020 19:15:13
- Last modified 21.11.2024 05:31:37
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2020-3717
- EPSS 0.28%
- Published 29.01.2020 19:15:13
- Last modified 21.11.2024 05:31:37
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
- EPSS 8.7%
- Published 29.01.2020 19:15:13
- Last modified 21.11.2024 05:31:37
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2015-6497
- EPSS 2.67%
- Published 15.01.2020 17:15:13
- Last modified 21.11.2024 02:35:05
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to e...
CVE-2019-8132
- EPSS 0.18%
- Published 06.11.2019 01:15:25
- Last modified 21.11.2024 04:49:20
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configurat...
CVE-2019-8145
- EPSS 0.18%
- Published 06.11.2019 01:15:25
- Last modified 21.11.2024 04:49:22
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.
CVE-2019-8156
- EPSS 1.11%
- Published 06.11.2019 01:15:25
- Last modified 21.11.2024 04:49:23
A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to ...
CVE-2019-8157
- EPSS 0.18%
- Published 06.11.2019 01:15:25
- Last modified 21.11.2024 04:49:23
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an invocation of error handling that acceses user input ...
CVE-2019-8158
- EPSS 0.19%
- Published 06.11.2019 01:15:25
- Last modified 21.11.2024 04:49:23
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without val...
CVE-2019-8229
- EPSS 0.19%
- Published 06.11.2019 00:15:13
- Last modified 21.11.2024 04:49:31
In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.