Show filters
355 Total Results
Displaying 201-210 of 355
Sort by:
Attacker Value
Unknown

CVE-2020-3716

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-3758

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Attacker Value
Unknown

CVE-2020-3718

Disclosure Date: January 29, 2020 (last updated November 27, 2024)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2015-6497

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via the productData parameter to index.php/api/v2_soap.
Attacker Value
Unknown

CVE-2019-8158

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted key/value GET request data allows an attacker to limited access to underlying XML data.
Attacker Value
Unknown

CVE-2019-8157

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an invocation of error handling that acceses user input without sanitization.
Attacker Value
Unknown

CVE-2019-8156

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to enable remote code execution.
Attacker Value
Unknown

CVE-2019-8145

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.
Attacker Value
Unknown

CVE-2019-8132

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" dashboard.
Attacker Value
Unknown

CVE-2019-8232

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import feature can execute arbitrary code through a race condition that allows webserver configuration file modification.