Magento

Magento

222 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 36.43%
  • Published 10.04.2019 18:29:01
  • Last modified 21.11.2024 04:47:38

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to ...

  • EPSS 0.03%
  • Published 08.01.2018 22:29:00
  • Last modified 21.11.2024 04:08:32

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.

  • EPSS 0.1%
  • Published 30.12.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.

  • EPSS 0.2%
  • Published 26.09.2017 01:29:00
  • Last modified 20.04.2025 01:37:25

Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the refer...

Exploit
  • EPSS 0.07%
  • Published 20.09.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

Exploit
  • EPSS 87.06%
  • Published 23.01.2017 21:59:01
  • Last modified 20.04.2025 01:37:25

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

Exploit
  • EPSS 0.13%
  • Published 15.04.2016 14:59:13
  • Last modified 12.04.2025 10:46:40

The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition before 1.14.2.3 and Magento Community Edition before 1.9.2.3 allows remote attackers to obtain sensitive o...

Exploit
  • EPSS 2.15%
  • Published 29.04.2015 22:59:04
  • Last modified 12.04.2025 10:46:40

The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not restrict the stream wrapper used in a template path, which allows remote administrators to inclu...

  • EPSS 8.96%
  • Published 29.04.2015 22:59:03
  • Last modified 12.04.2025 10:46:40

Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

Exploit
  • EPSS 3.82%
  • Published 29.04.2015 22:59:02
  • Last modified 12.04.2025 10:46:40

PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary PHP code via...