<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Magento</title>
  <link>https://cvedaily.com/pages/tags/magento.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/magento.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Magento</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:43 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45247 – Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45247</guid>
    <pubDate>Tue, 26 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45247</strong></p>
  <p>Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its d…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42458 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42458</guid>
    <pubDate>Fri, 15 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42458</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -> System -> Import/Export -> Dataflow - Profiles. This vulnerability is fixed in 20.18.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-87</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42207 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42207</guid>
    <pubDate>Fri, 15 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42207</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, Mage_ProductAlert_AddController::stockAction() reads the uenc query parameter and passes it directly to $this->_redirectUrl($backUrl) without calling $this->_isUrlInternal(). When the…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42155 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42155</guid>
    <pubDate>Fri, 15 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42155</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, the XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG). All inputs to…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40488 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40488</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40488</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option file upload in OpenMage LTS uses an incomplete blocklist (`forbidden_extensions = php,exe`) to prevent dangerous file uploads. This blocklist can be t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40098 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40098</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40098</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the shared wishlist add-to-cart endpoint authorizes access with a public `sharing_code`, but loads the acted-on wishlist item by a separate global `wishlist_item_id` and never…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25525 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25525</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25525</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the Dataflow module in OpenMage LTS uses a weak blacklist filter (`str_replace('../', '', $input)`) to prevent path traversal attacks. This filter can be bypassed using pattern…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25524 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25524</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25524</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()` can trigger deserialization when processing `phar://` stream wrapper paths. OpenMage LTS uses these…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25523 – Magento-lts is a long-term support alternative to Magento Community Edition (CE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25523</guid>
    <pubDate>Wed, 04 Feb 2026 22:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25523</strong></p>
  <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64174 – Magento-lts is a long-term support alternative to Magento Community Edition (CE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64174</guid>
    <pubDate>Thu, 06 Nov 2025 21:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64174</strong></p>
  <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Unescaped translation strings and URLs are printed into contexts inside a…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-60991 – A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60991</guid>
    <pubDate>Wed, 01 Oct 2025 18:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-60991</strong></p>
  <p>A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58669 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58669</guid>
    <pubDate>Mon, 22 Sep 2025 19:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58669</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modern Minds Magento 2 WordPress Integration m2wp allows Stored XSS.This issue affects Magento 2 WordPress Integration: from n/a through <= 1.4.2.1.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-27400 – Magento Long Term Support (LTS) is an unofficial, community-driven project provi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27400</guid>
    <pubDate>Fri, 28 Feb 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-27400</strong></p>
  <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Versions prior to 20.12.3 and 20.13.0 contain a vulnerability that allows script execution in the admin panel which could lead to cross-site scripting against authenticated admin users. The attack requi…</p>
  <p><strong>CVSS:</strong> 2.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41676 – Magento-lts is a long-term support alternative to Magento Community Edition (CE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41676</guid>
    <pubDate>Mon, 29 Jul 2024 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41676</strong></p>
  <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping a…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34379 – Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooComm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34379</guid>
    <pubDate>Wed, 17 Jan 2024 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34379</strong></p>
  <p>Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: Magento to WooCommerce Migration: from n/a through 2.0.0.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41879 – Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41879</guid>
    <pubDate>Mon, 11 Sep 2023 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41879</strong></p>
  <p>Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36036 – Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36036</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36036</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving rem…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36023 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36023</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36023</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36021 – Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36021</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36021</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege could leverage this vulnerability to achieve remote code execution on the system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33353 – Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33353</guid>
    <pubDate>Wed, 08 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33353</strong></p>
  <p>Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33352 – An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33352</guid>
    <pubDate>Wed, 08 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33352</strong></p>
  <p>An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33351 – Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33351</guid>
    <pubDate>Wed, 08 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33351</strong></p>
  <p>Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41143 – OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41143</guid>
    <pubDate>Fri, 27 Jan 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41143</strong></p>
  <p>OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4.22 and 20.0.19 contain a patch for this issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21395 – Magneto LTS (Long Term Support) is a community developed alternative to the Mage...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21395</guid>
    <pubDate>Fri, 27 Jan 2023 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21395</strong></p>
  <p>Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior to 19.4.22 and 20.0.19 are vulnerable to Cross-Site Request Forgery. The password reset form is vulnerable to CSRF between the time the reset password link is clicked and user submits new password. This issue is patched in versions 19.4.22 and 20.0.19. There are no workarounds.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36433 – The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36433</guid>
    <pubDate>Tue, 29 Nov 2022 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36433</strong></p>
  <p>The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-35501 – Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35501</guid>
    <pubDate>Wed, 23 Nov 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-35501</strong></p>
  <p>Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36432 – The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36432</guid>
    <pubDate>Thu, 17 Nov 2022 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36432</strong></p>
  <p>The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28567 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28567</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28567</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-28566 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28566</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-28566</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploitation could lead to the disclosure of document root path by an unauthenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36044 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36044</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36044</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36043 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36043</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36043</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36042 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36042</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36042</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestricted file upload which can result in remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36041 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36041</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36041</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could upload a specially crafted file in the 'pub/media` directory could lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36040 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36040</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36040</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36039 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36039</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36039</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the `quoteId` parameter. An attacker can abuse this vulnerability to disclose sensitive information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36038 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36038</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36038</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the Multishipping Module. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36037 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36037</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36037</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36035 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36035</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36035</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could make a crafted request to the Adobe Stock API to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36034 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36034</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36034</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36033 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36033</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36033</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36032 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36032</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36032</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36031 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36031</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36031</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a Path Traversal vulnerability via the `theme[preview_image]` parameter. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36030 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36030</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36030</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36029 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36029</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36029</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36028 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36028</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36028</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36027 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36027</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36027</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36026 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36026</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36026</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36025 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36025</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36025</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges can leverage this vulnerability to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36024 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36024</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36024</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36022 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36022</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36022</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36020 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36020</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36020</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36012 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36012</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36012</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-840</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32759 – OpenMage magento-lts is an alternative to the Magento CE official releases. Due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32759</guid>
    <pubDate>Fri, 27 Aug 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32759</strong></p>
  <p>OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage versions 19.4.15 and 20.0.13 have a patch for this Issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32758 – OpenMage Magento LTS is an alternative to the Magento CE official releases. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32758</guid>
    <pubDate>Fri, 27 Aug 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32758</strong></p>
  <p>OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28585 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28585</guid>
    <pubDate>Mon, 28 Jun 2021 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28585</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New customer WebAPI.Successful exploitation could allow an attacker to send unsolicited spam e-mails.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28584 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28584</guid>
    <pubDate>Mon, 28 Jun 2021 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28584</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28583 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28583</guid>
    <pubDate>Mon, 28 Jun 2021 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28583</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an attacker to get unauthorized access to restricted resources.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-657</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28563 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28563</guid>
    <pubDate>Mon, 28 Jun 2021 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28563</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modification of customer data by an unauthenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28556 – Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28556</guid>
    <pubDate>Mon, 28 Jun 2021 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28556</strong></p>
  <p>Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32684 – magento-scripts contains scripts and configuration used by Create Magento App, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32684</guid>
    <pubDate>Mon, 14 Jun 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32684</strong></p>
  <p>magento-scripts contains scripts and configuration used by Create Magento App, a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2, after changing the function from synchronous to asynchronous there wasn't implemented handler in the start, stop, exec, and logs commands, effectively making them unusable. Version 1.5.3 contains patches for the problems.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21427 – Magento-lts is a long-term support alternative to Magento Community Edition (CE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21427</guid>
    <pubDate>Wed, 21 Apr 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21427</strong></p>
  <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted resources. This is a backport of CVE-2021-21024. The vulnerability is patched in versions 19.4.13 and 20.0.9.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21426 – Magento-lts is a long-term support alternative to Magento Community Edition (CE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21426</guid>
    <pubDate>Wed, 21 Apr 2021 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21426</strong></p>
  <p>Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 and 20.0.9 was back ported from Zend Framework 3. The vulnerability was assigned CVE-2021-3007 in Zend Framework.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21064 – Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21064</guid>
    <pubDate>Thu, 25 Feb 2021 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21064</strong></p>
  <p>Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21014 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21014</guid>
    <pubDate>Thu, 11 Feb 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21014</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21032 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21032</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21032</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of this issue could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21031 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21031</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21031</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21030 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21030</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21030</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21029 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21029</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21029</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21027 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21027</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21027</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21026 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21026</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21026</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21025 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21025</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21025</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21024 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21024</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21024</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21023 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21023</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21023</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21022 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21022</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21022</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module. Successful exploitation could lead to unauthorized access to restricted resources.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21020 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21020</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21020</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Successful exploitation could lead to unauthorized access to restricted resources.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21019 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21019</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21019</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21018 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21018</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21018</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21016 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21016</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21016</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21015 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21015</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21015</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26295 – OpenMage is a community-driven alternative to Magento CE. In OpenMage before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26295</guid>
    <pubDate>Thu, 21 Jan 2021 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26295</strong></p>
  <p>OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue solved</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26285 – OpenMage is a community-driven alternative to Magento CE. In OpenMage before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26285</guid>
    <pubDate>Thu, 21 Jan 2021 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26285</strong></p>
  <p>OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to import/export data and to create widget instances was able to inject an executable file on the server. The latest OpenMage Versions up from 19.4.9 and 20.0.5 have this Issue…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26252 – OpenMage is a community-driven alternative to Magento CE. In OpenMage before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26252</guid>
    <pubDate>Wed, 20 Jan 2021 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26252</strong></p>
  <p>OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to update product data to be able to store an executable file on the server and load it via layout xml. The latest OpenMage Versions up from 19.4.10 and 20.0.6 have this issue s…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21013 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21013</guid>
    <pubDate>Wed, 13 Jan 2021 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21013</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and update arbitrary information on another user's account.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21012 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21012</guid>
    <pubDate>Wed, 13 Jan 2021 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21012</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-24407 – Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24407</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-24407</strong></p>
  <p>Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import components.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-24406 – When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24406</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-24406</strong></p>
  <p>When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attackers if they are able to identify other exploitable vulnerabilities in the environment.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24405 – Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect per...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24405</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24405</strong></p>
  <p>Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-24404 – Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect per...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24404</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-24404</strong></p>
  <p>Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-24403 – Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24403</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-24403</strong></p>
  <p>Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24402 – Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect per...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24402</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24402</strong></p>
  <p>Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to delete customer details via the REST API without authorization.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24401 – Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24401</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24401</strong></p>
  <p>Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24400 – Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24400</guid>
    <pubDate>Mon, 09 Nov 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24400</strong></p>
  <p>Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15244 – In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15244</guid>
    <pubDate>Wed, 21 Oct 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15244</strong></p>
  <p>In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue is patched in versions 19.4.8 and 20.0.4.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24408 – Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24408</guid>
    <pubDate>Fri, 16 Oct 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24408</strong></p>
  <p>Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-5777 – MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5777</guid>
    <pubDate>Tue, 01 Sep 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-5777</strong></p>
  <p>MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13404 – The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13404</guid>
    <pubDate>Wed, 05 Aug 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13404</strong></p>
  <p>The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9692 – Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9692</guid>
    <pubDate>Wed, 29 Jul 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9692</strong></p>
  <p>Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9691 – Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9691</guid>
    <pubDate>Wed, 29 Jul 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9691</strong></p>
  <p>Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9690 – Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9690</guid>
    <pubDate>Wed, 29 Jul 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9690</strong></p>
  <p>Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9689 – Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path trav...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9689</guid>
    <pubDate>Wed, 29 Jul 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9689</strong></p>
  <p>Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9689">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
