magento/community-edition
Packagist353 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting magento/community-editionpage 6 of 8
- CVE-2023-38249HIGHCVSS 8.0EG 8.0fixed in 2.4.7-beta2, 2.4.6-p3, 2.4.5-p5 or 2.4.4-p6, by version range2023-10-13
vulnerable: 2.4.4-p1, 2.4.4-p2, 2.4.4-p3, 2.4.4-p4, 2.4.4-p5
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabil…
- CVE-2023-38250HIGHCVSS 8.0EG 8.0fixed in 2.4.7-beta2, 2.4.6-p3, 2.4.5-p5 or 2.4.4-p6, by version range2023-10-13
vulnerable: 2.4.4-p1, 2.4.4-p2, 2.4.4-p3, 2.4.4-p4, 2.4.4-p5
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabil…
- CVE-2023-38251MEDIUMCVSS 5.3EG 5.3fixed in 2.4.7-beta2, 2.4.6-p3, 2.4.5-p5 or 2.4.4-p6, by version range2023-10-13
vulnerable: 2.4.4-p1, 2.4.4-p2, 2.4.4-p3, 2.4.4-p4, 2.4.4-p5
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that could lead in minor application denial-of-s…
- CVE-2024-20716MEDIUMCVSS 4.9EG 4.9fixed in 2.4.6-p4, 2.4.5-p6 or 2.4.4-p7, by version range2024-02-15
vulnerable: 2.4.4-p1 ... 2.4.4-p6 (6 versions)
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnera…
- CVE-2024-20718MEDIUMCVSS 4.3EG 4.3fixed in 2.4.6-p4, 2.4.5-p6 or 2.4.4-p7, by version range2024-02-15
vulnerable: 2.4.4-p1 ... 2.4.4-p6 (6 versions)
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a vic…
- CVE-2024-20719CRITICALCVSS 9.1EG 9.1fixed in 2.4.6-p4, 2.4.5-p6 or 2.4.4-p7, by version range2024-02-15
vulnerable: 2.4.4-p1 ... 2.4.4-p6 (6 versions)
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaS…
- CVE-2024-20720CRITICALCVSS 9.1EG 9.1fixed in 2.4.6-p4, 2.4.5-p6 or 2.4.4-p7, by version range2024-02-15
vulnerable: 2.4.4-p1 ... 2.4.4-p6 (6 versions)
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an …
- CVE-2024-20758CRITICALCVSS 9.0EG 9.0fixed in 2.4.7, 2.4.6-p5, 2.4.5-p7 or 2.4.4-p8, by version range2024-04-10
vulnerable: 2.4.4-p1 ... 2.4.4-p7 (7 versions)
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution on the underlying filesystem. Exploitation of this issue…
- CVE-2024-20759HIGHCVSS 8.1EG 8.1fixed in 2.4.7, 2.4.6-p5, 2.4.5-p7 or 2.4.4-p8, by version range2024-04-10
vulnerable: 2.4.4-p1 ... 2.4.4-p7 (7 versions)
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable …
- CVE-2024-34102CRITICALCVSS 9.8EG 9.8⚠ KEVfixed in 2.4.6-p6, 2.4.5-p8 or 2.4.4-p9, by version range2024-06-13
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit…
- CVE-2024-34103HIGHCVSS 8.1EG 8.1fixed in 2.4.6-p6, 2.4.5-p8 or 2.4.4-p9, by version range2024-06-13
vulnerable: 0.1.0-alpha100 ... 2.4.4-p8 (146 versions)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized a…
- CVE-2024-34104HIGHCVSS 8.2EG 8.2fixed in 2.4.6-p6, 2.4.5-p8 or 2.4.4-p9, by version range2024-06-13
vulnerable: 0.1.0-alpha100 ... 2.4.4-p8 (146 versions)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass securit…
- CVE-2024-34105MEDIUMCVSS 4.8EG 4.8fixed in 2.4.6-p6, 2.4.5-p8 or 2.4.4-p9, by version range2024-06-13
vulnerable: 0.1.0-alpha100 ... 2.4.4-p8 (146 versions)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Ma…
- CVE-2024-34106MEDIUMCVSS 5.3EG 5.3fixed in 2.4.6-p6, 2.4.5-p8 or 2.4.4-p9, by version range2024-06-13
vulnerable: 0.1.0-alpha100 ... 2.4.4-p8 (146 versions)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to gain unauthori…
- CVE-2024-34107MEDIUMCVSS 5.3EG 5.3fixed in 2.4.6-p6, 2.4.5-p8 or 2.4.4-p9, by version range2024-06-13
vulnerable: 0.1.0-alpha100 ... 2.4.4-p8 (146 versions)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass securi…
- CVE-2024-34111MEDIUMCVSS 6.5EG 6.5fixed in 2.4.6-p6, 2.4.5-p8 or 2.4.4-p9, by version range2024-06-13
vulnerable: 0.1.0-alpha100 ... 2.4.4-p8 (146 versions)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the …
- CVE-2024-39398HIGHCVSS 7.4EG 7.4fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a security feature bypass. An attacker could exploit…
- CVE-2024-39399HIGHCVSS 7.7EG 7.7fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A low…
- CVE-2024-39400HIGHCVSS 8.1EG 8.1fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker to inject and execute arbitrary JavaScript co…
- CVE-2024-39401HIGHCVSS 8.4EG 8.4fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execut…
- CVE-2024-39402HIGHCVSS 8.4EG 8.4fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execut…
- CVE-2024-39403HIGHCVSS 7.6EG 7.6fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form…
- CVE-2024-39404MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39405MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39406MEDIUMCVSS 6.8EG 6.8fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An ad…
- CVE-2024-39407MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39408MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changeson beh…
- CVE-2024-39409MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on be…
- CVE-2024-39410MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on be…
- CVE-2024-39411MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39412MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39413MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39414MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39415MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39416MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39417MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39418MEDIUMCVSS 5.4EG 5.4fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39419MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p2, 2.4.6-p7, 2.4.5-p9 or 2.4.4-p10, by version range2024-08-14
vulnerable: 2.4.7
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-45116HIGHCVSS 8.1EG 8.1fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a…
- CVE-2024-45117HIGHCVSS 7.6EG 7.6fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to rea…
- CVE-2024-45118MEDIUMCVSS 6.5EG 6.5fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerabilit…
- CVE-2024-45119MEDIUMCVSS 4.9EG 4.9fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can f…
- CVE-2024-45120LOWCVSS 3.1EG 3.1fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vuln…
- CVE-2024-45121MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerabilit…
- CVE-2024-45122MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerabilit…
- CVE-2024-45123MEDIUMCVSS 6.1EG 6.1fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, mal…
- CVE-2024-45124MEDIUMCVSS 5.3EG 5.3fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass se…
- CVE-2024-45125MEDIUMCVSS 4.3EG 4.3fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability…
- CVE-2024-45127MEDIUMCVSS 4.8EG 4.8fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields…
- CVE-2024-45128MEDIUMCVSS 5.4EG 5.4fixed in 2.4.7-p3, 2.4.6-p8, 2.4.5-p10 or 2.4.4-p11, by version range2024-10-10
vulnerable: 2.4.4
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability…
Check whether magento/community-edition is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for magento/community-edition CVEs against the assets you own.
Book a Demo →