Magento records
224 published records for vendor magento.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.4%
- Pre-auth RCE
- 17
- With a fix record
- 91.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')65
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')10
- CWE-639 Authorization Bypass Through User-Controlled Key8
- CWE-434 Unrestricted Upload of File with Dangerous Type8
- CWE-285 Improper Authorization7
The weakness classes this vendor ships most often: where to look.
CWEAll records
224 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
67This week | CVE-2016-4010Weaponized | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedmagento · magento · CWE-74 | Critical9.8 | — | 92.9% | Jan 23, 2017 |
45Plan | CVE-2019-7139Proof of concept | An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data magento · magento · CWE-89 | Critical9.8 | — | 18.3% | Apr 10, 2019 |
44Plan | CVE-2021-21029No exploit | Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Executionmagento · magento · CWE-79 | Medium4.8 | — | 84.6% | Feb 11, 2021 |
43Plan | CVE-2015-1397Proof of concept | SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1magento · magento · CWE-89 | Medium6.5 | — | 56.7% | Apr 29, 2015 |
43Plan | CVE-2020-3716No exploit | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted damagento · magento · CWE-502 | Critical9.8 | — | 14.0% | Jan 29, 2020 |
42Plan | CVE-2020-9664No exploit | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.magento · magento · CWE-502 | Critical9.8 | — | 8.4% | Jul 22, 2020 |
41Plan | CVE-2020-3718No exploit | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.magento · magento | Critical9.8 | — | 7.5% | Jan 29, 2020 |
41Plan | CVE-2020-9631No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Critical9.8 | — | 7.4% | Jun 26, 2020 |
41Plan | CVE-2020-9632No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Critical9.8 | — | 7.4% | Jun 26, 2020 |
41Plan | CVE-2020-9582No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Critical9.8 | — | 5.7% | Jun 26, 2020 |
41Plan | CVE-2020-9583No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Critical9.8 | — | 5.7% | Jun 26, 2020 |
41Plan | CVE-2020-9578No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Critical9.8 | — | 5.7% | Jun 26, 2020 |
41Plan | CVE-2020-9576No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Critical9.8 | — | 5.7% | Jun 26, 2020 |
41Plan | CVE-2020-9579No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Critical9.8 | — | 5.0% | Jun 26, 2020 |
41Plan | CVE-2020-9580No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Critical9.8 | — | 5.0% | Jun 26, 2020 |
40Plan | CVE-2022-34258No exploit | Adobe Commerce Stored XSS Arbitrary code executionadobe · commerce · CWE-79 | Medium4.8 | — | 68.5% | Aug 16, 2022 |
40Plan | CVE-2020-9691No exploit | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.magento · magento · CWE-79 | Critical9.6 | — | 6.0% | Jul 29, 2020 |
40Plan | CVE-2020-9585No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth secmagento · magento | Critical9.8 | — | 4.9% | Jun 26, 2020 |
40Plan | CVE-2020-9630No exploit | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic errormagento · magento | Critical9.8 | — | 4.0% | Jun 26, 2020 |
40Plan | CVE-2019-8144No exploit | A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento | Critical9.8 | — | 2.5% | Nov 5, 2019 |
40Plan | CVE-2019-8135No exploit | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-74 | Critical9.8 | — | 2.5% | Nov 5, 2019 |
40Plan | CVE-2019-8149No exploit | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-613 | Critical9.8 | — | 2.1% | Nov 5, 2019 |
40Plan | CVE-2022-34256No exploit | Adobe Commerce Improper Authorization Privilege escalationadobe · commerce · CWE-285 | Critical9.8 | — | 2.1% | Aug 16, 2022 |
39Monitor | CVE-2014-1634No exploit | SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_categorymagento · advanced newsletter · CWE-89 | Critical9.8 | — | 1.4% | Mar 9, 2020 |
39Monitor | CVE-2015-8707No exploit | Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, magento · magento · CWE-200 | Critical9.8 | — | 1.3% | Sep 25, 2017 |
- CVE-2016-401067This week
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted
CriticalCVSS 9.8WeaponizedEPSS 93%magento · magentoJan 23, 2017
- CVE-2019-713945Plan
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data
CriticalCVSS 9.8Proof of conceptEPSS 18%magento · magentoApr 10, 2019
- CVE-2021-2102944Plan
Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Execution
MediumCVSS 4.8No exploitEPSS 85%magento · magentoFeb 11, 2021
- CVE-2015-139743Plan
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1
MediumCVSS 6.5Proof of conceptEPSS 57%magento · magentoApr 29, 2015
- CVE-2020-371643Plan
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted da
CriticalCVSS 9.8No exploitEPSS 14%magento · magentoJan 29, 2020
- CVE-2020-966442Plan
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.
CriticalCVSS 9.8No exploitEPSS 8%magento · magentoJul 22, 2020
- CVE-2020-371841Plan
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.
CriticalCVSS 9.8No exploitEPSS 8%magento · magentoJan 29, 2020
- CVE-2020-963141Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
CriticalCVSS 9.8No exploitEPSS 7%magento · magentoJun 26, 2020
- CVE-2020-963241Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
CriticalCVSS 9.8No exploitEPSS 7%magento · magentoJun 26, 2020
- CVE-2020-958241Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
CriticalCVSS 9.8No exploitEPSS 6%magento · magentoJun 26, 2020
- CVE-2020-958341Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
CriticalCVSS 9.8No exploitEPSS 6%magento · magentoJun 26, 2020
- CVE-2020-957841Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
CriticalCVSS 9.8No exploitEPSS 6%magento · magentoJun 26, 2020
- CVE-2020-957641Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
CriticalCVSS 9.8No exploitEPSS 6%magento · magentoJun 26, 2020
- CVE-2020-957941Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
CriticalCVSS 9.8No exploitEPSS 5%magento · magentoJun 26, 2020
- CVE-2020-958041Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
CriticalCVSS 9.8No exploitEPSS 5%magento · magentoJun 26, 2020
- CVE-2022-3425840Plan
Adobe Commerce Stored XSS Arbitrary code execution
MediumCVSS 4.8No exploitEPSS 69%adobe · commerceAug 16, 2022
- CVE-2020-969140Plan
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.
CriticalCVSS 9.6No exploitEPSS 6%magento · magentoJul 29, 2020
- CVE-2020-958540Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth sec
CriticalCVSS 9.8No exploitEPSS 5%magento · magentoJun 26, 2020
- CVE-2020-963040Plan
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error
CriticalCVSS 9.8No exploitEPSS 4%magento · magentoJun 26, 2020
- CVE-2019-814440Plan
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
CriticalCVSS 9.8No exploitEPSS 2%magento · magentoNov 5, 2019
- CVE-2019-813540Plan
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
CriticalCVSS 9.8No exploitEPSS 2%magento · magentoNov 5, 2019
- CVE-2019-814940Plan
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
CriticalCVSS 9.8No exploitEPSS 2%magento · magentoNov 5, 2019
- CVE-2022-3425640Plan
Adobe Commerce Improper Authorization Privilege escalation
CriticalCVSS 9.8No exploitEPSS 2%adobe · commerceAug 16, 2022
- CVE-2014-163439Monitor
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category
CriticalCVSS 9.8No exploitEPSS 1%magento · advanced newsletterMar 9, 2020
- CVE-2015-870739Monitor
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use,
CriticalCVSS 9.8No exploitEPSS 1%magento · magentoSep 25, 2017