magento/community-edition
Packagist353 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting magento/community-editionpage 3 of 8
- CVE-2019-8133MEDIUMCVSS 6.5EG 6.5fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with privileges to generate sitemaps can bypass configuration that restricts directory access. The bypass allows overwrit…
- CVE-2019-8134HIGHCVSS 8.8EG 8.8fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with marketing privileges can execute arbitrary SQL queries in the database when accessing email template variables.
- CVE-2019-8135CRITICALCVSS 9.8EG 9.8fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which …
- CVE-2019-8136CRITICALCVSS 9.8EG 9.8fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.
- CVE-2019-8137HIGHCVSS 8.8EG 8.8fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custo…
- CVE-2019-8138MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not …
- CVE-2019-8139MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript code into the dynamic block when invoking page builder on a product.
- CVE-2019-8140MEDIUMCVSS 4.9EG 4.9fixed in 2.2.10 or 2.3.3, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2, 2.3.2-p2
An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to tr…
- CVE-2019-8141HIGHCVSS 7.2EG 7.2fixed in 2.1.19, 2.2.10 or 2.3.3, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2, 2.3.2-p2
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute arbitrary code thr…
- CVE-2019-8142MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via title of an order when configuring sales paymen…
- CVE-2019-8143MEDIUMCVSS 6.5EG 6.5fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information sto…
- CVE-2019-8144CRITICALCVSS 9.8EG 9.8fixed in 2.3.2-p12019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.
- CVE-2019-8145MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the produc…
- CVE-2019-8146MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.
- CVE-2019-8147MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via customer attribute label.
- CVE-2019-8148MEDIUMCVSS 4.8EG 4.8fixed in 2.3.2-p22019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.
- CVE-2019-8149CRITICALCVSS 9.8EG 9.8fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent …
- CVE-2019-8150HIGHCVSS 8.8EG 8.8fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate layouts and images can insert a malicious payload into the page layout.
- CVE-2019-8151HIGHCVSS 7.2EG 7.2fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to manipulate shippment settings can execute arbitrary code through server-sid…
- CVE-2019-8152MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse …
- CVE-2019-8153MEDIUMCVSS 6.1EG 6.1fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the `es…
- CVE-2019-8154HIGHCVSS 8.8EG 8.8fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file…
- CVE-2019-8156HIGHCVSS 7.2EG 7.2fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api e…
- CVE-2019-8157MEDIUMCVSS 5.4EG 5.4fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an invocation of error handling that acceses …
- CVE-2019-8158CRITICALCVSS 9.8EG 9.8fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine …
- CVE-2019-8159HIGHCVSS 8.8EG 8.8fixed in 2.2.10 or 2.3.2-p2, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion…
- CVE-2019-8232MEDIUMCVSS 6.6EG 6.6fixed in 2.2.10 or 2.3.2-p1, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2
In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import feature can execute arbitrary code through…
- CVE-2019-8233MEDIUMCVSS 6.1EG 6.1fixed in 2.2.10 or 2.3.3, by version range2019-11-06
vulnerable: 2.3.0, 2.3.1, 2.3.2, 2.3.2-p2
In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of the sanitization engine ignoring HTML comments.
- CVE-2020-24400HIGHCVSS 7.1EG 7.1fixed in 2.3.6 or 2.4.1, by version range2020-11-09
vulnerable: 2.4.0, 2.4.0-p1
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the produ…
- CVE-2020-24401MEDIUMCVSS 6.5EG 6.5fixed in 2.4.12020-11-09
vulnerable: 0.1.0-alpha100 ... 2.4.0-p1 (128 versions)
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's ac…
- CVE-2020-24402MEDIUMCVSS 4.9EG 4.9fixed in 2.3.6 or 2.4.1, by version range2020-11-09
vulnerable: 2.4.0, 2.4.0-p1
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to …
- CVE-2020-24403LOWCVSS 2.7EG 2.7fixed in 2.3.6 or 2.4.1, by version range2020-11-09
vulnerable: 2.4.0, 2.4.0-p1
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to …
- CVE-2020-24404LOWCVSS 2.7EG 2.7fixed in 2.3.6 or 2.4.1, by version range2020-11-09
vulnerable: 2.4.0, 2.4.0-p1
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms page…
- CVE-2020-24405MEDIUMCVSS 4.3EG 4.3fixed in 2.3.6 or 2.4.1, by version range2020-11-09
vulnerable: 2.4.0, 2.4.0-p1
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authoriz…
- CVE-2020-24406LOWCVSS 3.7EG 3.7fixed in 2.3.6 or 2.4.1, by version range2020-11-09
vulnerable: 2.4.0, 2.4.0-p1
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attacker…
- CVE-2020-24407CRITICALCVSS 9.1EG 9.1fixed in 2.4.12020-11-09
vulnerable: 0.1.0-alpha100 ... 2.4.0-p1 (128 versions)
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions t…
- CVE-2020-24408MEDIUMCVSS 6.1EG 6.1fixed in 2.4.12020-10-16
vulnerable: 0.1.0-alpha100 ... 2.4.0-p1 (128 versions)
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attack…
- CVE-2020-3715MEDIUMCVSS 6.1EG 6.1fixed in 2.3.4 or 2.2.11, by version range2020-01-29
vulnerable: 0.1.0-alpha100 ... 2.2.9 (107 versions)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-3716CRITICALCVSS 9.8EG 9.8fixed in 2.2.11 or 2.3.4, by version range2020-01-29
vulnerable: 2.3.0 ... 2.3.3-p1 (6 versions)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-3717MEDIUMCVSS 5.3EG 5.3fixed in 2.2.11 or 2.3.4, by version range2020-01-29
vulnerable: 2.3.0 ... 2.3.3-p1 (6 versions)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-3718CRITICALCVSS 9.8EG 9.8fixed in 2.3.4 or 2.2.11, by version range2020-01-29
vulnerable: 0.1.0-alpha100 ... 2.2.9 (107 versions)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-3719HIGHCVSS 7.5EG 7.5fixed in 2.3.4 or 2.2.11, by version range2020-01-29
vulnerable: 0.1.0-alpha100 ... 2.2.9 (107 versions)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-3758MEDIUMCVSS 6.1EG 6.1fixed in 2.3.4 or 2.2.11, by version range2020-01-29
vulnerable: 0.1.0-alpha100 ... 2.2.9 (107 versions)
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-9576CRITICALCVSS 9.8EG 9.8fixed in 2.3.4-p2 or 2.2.12, by version range2020-06-26
vulnerable: 0.1.0-alpha100 ... 2.2.9 (108 versions)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9577MEDIUMCVSS 6.1EG 6.1fixed in 2.3.4-p22020-06-26
vulnerable: 0.1.0-alpha100 ... 2.3.4 (115 versions)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure .
- CVE-2020-9578CRITICALCVSS 9.8EG 9.8fixed in 2.3.4-p22020-06-26
vulnerable: 2.3.0 ... 2.3.4 (7 versions)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9579CRITICALCVSS 9.8EG 9.8fixed in 2.3.4-p22020-06-26
vulnerable: 2.3.0 ... 2.3.4 (7 versions)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9580CRITICALCVSS 9.8EG 9.8fixed in 2.3.4-p22020-06-26
vulnerable: 2.3.0 ... 2.3.4 (7 versions)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9581MEDIUMCVSS 6.1EG 6.1fixed in 2.3.4-p22020-06-26
vulnerable: 2.3.0 ... 2.3.4 (7 versions)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-9582CRITICALCVSS 9.8EG 9.8fixed in 2.3.4-p2 or 2.2.12, by version range2020-06-26
vulnerable: 0.1.0-alpha100 ... 2.2.9 (108 versions)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Check whether magento/community-edition is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for magento/community-edition CVEs against the assets you own.
Book a Demo →