Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Magento HIGH 7.2
CVE-2019-7912

A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by a…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.2
CVE-2019-7913

A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7904

Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable …

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.3
CVE-2019-7898

Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.3
CVE-2019-7899

Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Ma…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Magento HIGH 8.8
CVE-2019-7876

A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 8.8
CVE-2019-7885

Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, …

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.5
CVE-2019-7886

A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is u…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.3
CVE-2019-7890

An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7874

A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can re…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7888

An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticat…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7889

An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magen…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Magento MEDIUM 6.1
CVE-2019-7877

A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior t…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.4
CVE-2019-7881

A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.4
CVE-2019-7882

A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Magento HIGH 8.8
CVE-2019-7865

A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magent…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 8.8
CVE-2019-7871

A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbit…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.5
CVE-2019-7858

A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive infor…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.5
CVE-2019-7859

A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could re…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.5
CVE-2019-7860

A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 pri…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.5
CVE-2019-7861

Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento …

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7872

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.3
CVE-2019-7864

An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento …

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento HIGH 7.5
CVE-2019-7849

A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior t…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,950 2019-08-02
Magento HIGH 7.5
CVE-2019-7854

An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can l…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7851

A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to uninten…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.3
CVE-2019-7852

A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specifi…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.3
CVE-2019-7855

A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento CRITICAL 9.8
CVE-2019-7139EPSS 18%

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. …

Fix: 1.9.4.1 / 1.14.4.1+
Fix from $2,300 2019-04-10
Magento MEDIUM 6.5
CVE-2018-5301

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an a…

Fix: 2.0.10 / 2.1.2+
Fix from $1,600 2018-01-08