<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Magento (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/magento.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/magento-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Magento (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:43 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45247 – Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45247</guid>
    <pubDate>Tue, 26 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45247</strong></p>
  <p>Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its d…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42155 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42155</guid>
    <pubDate>Fri, 15 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42155</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, the XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG). All inputs to…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40488 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40488</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40488</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option file upload in OpenMage LTS uses an incomplete blocklist (`forbidden_extensions = php,exe`) to prevent dangerous file uploads. This blocklist can be t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25524 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25524</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25524</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()` can trigger deserialization when processing `phar://` stream wrapper paths. OpenMage LTS uses these…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-60991 – A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60991</guid>
    <pubDate>Wed, 01 Oct 2025 18:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-60991</strong></p>
  <p>A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41879 – Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41879</guid>
    <pubDate>Mon, 11 Sep 2023 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41879</strong></p>
  <p>Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36036 – Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36036</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36036</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving rem…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36023 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36023</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36023</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36021 – Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36021</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36021</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution on the system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33353 – Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33353</guid>
    <pubDate>Wed, 08 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33353</strong></p>
  <p>Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33352 – An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33352</guid>
    <pubDate>Wed, 08 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33352</strong></p>
  <p>An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33351 – Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33351</guid>
    <pubDate>Wed, 08 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33351</strong></p>
  <p>Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41143 – OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41143</guid>
    <pubDate>Fri, 27 Jan 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41143</strong></p>
  <p>OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4.22 and 20.0.19 contain a patch for this issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36044 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36044</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36044</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36043 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36043</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36043</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36042 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36042</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36042</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestricted file upload which can result in remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36041 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36041</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36041</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could upload a specially crafted file in the 'pub/media` directory could lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36040 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36040</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36040</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36035 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36035</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36035</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could make a crafted request to the Adobe Stock API to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36034 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36034</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36034</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36033 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36033</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36033</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36032 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36032</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36032</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36031 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36031</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36031</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a Path Traversal vulnerability via the `theme[preview_image]` parameter. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36030 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36030</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36030</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36029 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36029</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36029</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36028 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36028</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36028</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36025 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36025</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36025</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges can leverage this vulnerability to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36024 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36024</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36024</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36022 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36022</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36022</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36020 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36020</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36020</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32759 – OpenMage magento-lts is an alternative to the Magento CE official releases. Due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32759</guid>
    <pubDate>Fri, 27 Aug 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32759</strong></p>
  <p>OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage versions 19.4.15 and 20.0.13 have a patch for this Issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32758 – OpenMage Magento LTS is an alternative to the Magento CE official releases. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32758</guid>
    <pubDate>Fri, 27 Aug 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32758</strong></p>
  <p>OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28583 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28583</guid>
    <pubDate>Mon, 28 Jun 2021 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28583</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-657</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21427 – Magento-lts is a long-term support alternative to Magento Community Edition (CE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21427</guid>
    <pubDate>Wed, 21 Apr 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21427</strong></p>
  <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted resources. This is a backport of CVE-2021-21024. The vulnerability is patched in versions 19.4.13 and 20.0.9.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21426 – Magento-lts is a long-term support alternative to Magento Community Edition (CE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21426</guid>
    <pubDate>Wed, 21 Apr 2021 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21426</strong></p>
  <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 and 20.0.9 was back ported from Zend Framework 3. The vulnerability was assigned CVE-2021-3007 in Zend Framework.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21014 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21014</guid>
    <pubDate>Thu, 11 Feb 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21014</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21030 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21030</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21030</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21025 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21025</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21025</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21024 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21024</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21024</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21019 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21019</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21019</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21018 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21018</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21018</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21016 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21016</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21016</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21015 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21015</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21015</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26295 – OpenMage is a community-driven alternative to Magento CE. In OpenMage before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26295</guid>
    <pubDate>Thu, 21 Jan 2021 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26295</strong></p>
  <p>OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26285 – OpenMage is a community-driven alternative to Magento CE. In OpenMage before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26285</guid>
    <pubDate>Thu, 21 Jan 2021 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26285</strong></p>
  <p>OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to import/export data and to create widget instances was able to inject an executable file on the server. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26252 – OpenMage is a community-driven alternative to Magento CE. In OpenMage before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26252</guid>
    <pubDate>Wed, 20 Jan 2021 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26252</strong></p>
  <p>OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to update product data to be able to store an executable file on the server and load it via layout xml. The latest OpenMage Versions up from 19.4.10 and 20.0.6 have this issue s…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21013 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21013</guid>
    <pubDate>Wed, 13 Jan 2021 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21013</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and update arbitrary information on another user's account.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-24407 – Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24407</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-24407</strong></p>
  <p>Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24400 – Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24400</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24400</strong></p>
  <p>Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15244 – In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15244</guid>
    <pubDate>Wed, 21 Oct 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15244</strong></p>
  <p>In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-5777 – MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5777</guid>
    <pubDate>Tue, 01 Sep 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-5777</strong></p>
  <p>MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13404 – The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13404</guid>
    <pubDate>Wed, 05 Aug 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13404</strong></p>
  <p>The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9691 – Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9691</guid>
    <pubDate>Wed, 29 Jul 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9691</strong></p>
  <p>Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9664 – Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9664</guid>
    <pubDate>Wed, 22 Jul 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9664</strong></p>
  <p>Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9632 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9632</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9632</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9631 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9631</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9631</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9630 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9630</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9630</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9591 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9591</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9591</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin panel.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9588 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9588</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9588</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9587 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9587</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9587</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9585 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9585</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9585</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9583 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9583</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9583</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9582 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9582</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9582</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9580 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9580</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9580</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9579 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9579</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9579</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9578 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9578</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9578</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9576 – Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9576</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9576</strong></p>
  <p>Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-1634 – SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1634</guid>
    <pubDate>Mon, 09 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-1634</strong></p>
  <p>SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8818 – An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8818</guid>
    <pubDate>Tue, 25 Feb 2020 02:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8818</strong></p>
  <p>An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback reques…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-6091 – Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6091</guid>
    <pubDate>Thu, 13 Feb 2020 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-6091</strong></p>
  <p>Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3719 – Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3719</guid>
    <pubDate>Wed, 29 Jan 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3719</strong></p>
  <p>Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3718 – Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3718</guid>
    <pubDate>Wed, 29 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3718</strong></p>
  <p>Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3716 – Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3716</guid>
    <pubDate>Wed, 29 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3716</strong></p>
  <p>Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-6497 – The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6497</guid>
    <pubDate>Wed, 15 Jan 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-6497</strong></p>
  <p>The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via the productData parameter to index.php/api/v2_soap.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8158 – An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8158</guid>
    <pubDate>Wed, 06 Nov 2019 01:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8158</strong></p>
  <p>An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted key/value GET request data allows an attacker to limited access to underlying XML data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8156 – A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8156</guid>
    <pubDate>Wed, 06 Nov 2019 01:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8156</strong></p>
  <p>A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to enable remote code execution.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8231 – In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8231</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8231</strong></p>
  <p>In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8230 – In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8230</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8230</strong></p>
  <p>In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute arbitrary code through a crafted support/output path.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8229 – In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8229</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8229</strong></p>
  <p>In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8159 – A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8159</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8159</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion and OS command injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8155 – Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8155</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8155</strong></p>
  <p>Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8154 – A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8154</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8154</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file that specifies product design update.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8151 – A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8151</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8151</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to manipulate shippment settings can execute arbitrary code through server-side request forgery due to unsafe handling of a carrier gateway.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8150 – A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8150</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8150</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate layouts and images can insert a malicious payload into the page layout.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8149 – Insecure authentication and session management vulnerability exists in Magento 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8149</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8149</strong></p>
  <p>Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8144 – A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8144</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8144</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8141 – A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8141</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8141</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute arbitrary code through a Phar deserialization vulnerability in the import functionality.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8137 – A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8137</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8137</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout update.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8136 – An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8136</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8136</strong></p>
  <p>An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8135 – A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8135</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8135</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8134 – A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8134</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8134</strong></p>
  <p>A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with marketing privileges can execute arbitrary SQL queries in the database when accessing email template variables.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8130 – A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8130</guid>
    <pubDate>Wed, 06 Nov 2019 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8130</strong></p>
  <p>A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with store manipulation privileges can execute arbitrary SQL queries by getting access to the database connection through group instance in email templates.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8127 – A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8127</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8127</strong></p>
  <p>A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to an account with Newsletter Template editing permission could exfiltrate the Admin login data, and reset their password, effectively performing a privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8125 – A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8125</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8125</strong></p>
  <p>A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x. An authenticated admin user can modify configuration parameters via crafted support configuration. The modification can lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8122 – A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8122</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8122</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with privileges to create products can craft custom layout update and use import product functionality to enable remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8121 – An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8121</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8121</strong></p>
  <p>An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8119 – A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Mag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8119</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8119</strong></p>
  <p>A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated admin user with import product privileges can delete files through bulk product import and inject code into XSLT file. The combination of these manipulations can lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8116 – Insecure authentication and session management vulnerability exists in Magento 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8116</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8116</strong></p>
  <p>Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8114 – A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8114</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8114</strong></p>
  <p>A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to import features can execute arbitrary code via crafted configuration archive file upload.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8112 – A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8112</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8112</strong></p>
  <p>A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can bypass the email confirmation mechanism via GET request that captures relevant account data obtained from the POST response related to new user creation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8112">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
