CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2019-8232

    Last Modified: 21 Nov 2024

    In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import feature can execute arbitrary code through a race condition that allows webserver configuration file modification.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2019-8233

    Last Modified: 21 Nov 2024

    In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of the sanitization engine ignoring HTML comments.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-8155

    Last Modified: 21 Nov 2024

    Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8154

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file that specifies product design update.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2019-8153

    Last Modified: 21 Nov 2024

    A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the `escapeURL()` function and execute a malicious XSS payload.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8152

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8151

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to manipulate shippment settings can execute arbitrary code through server-side request forgery due to unsafe handling of a carrier gateway.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8150

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate layouts and images can insert a malicious payload into the page layout.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-8149

    Last Modified: 21 Nov 2024

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.

    Published: 5 Nov 2019
    4.8
    Medium

    CVE-2019-8148

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8147

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via customer attribute label.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8146

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-8144

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2019-8143

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8142

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via title of an order when configuring sales payment methods for a store.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8141

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute arbitrary code through a Phar deserialization vulnerability in the import functionality.

    Published: 5 Nov 2019
    4.9
    Medium

    CVE-2019-8140

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to transform uploaded JPEG file into a PHP file.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8139

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript code into the dynamic block when invoking page builder on a product.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8138

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8137

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout update.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-8136

    Last Modified: 21 Nov 2024

    An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-8135

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8134

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with marketing privileges can execute arbitrary SQL queries in the database when accessing email template variables.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2019-8133

    Last Modified: 21 Nov 2024

    A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with privileges to generate sitemaps can bypass configuration that restricts directory access. The bypass allows overwrite of a subset of configuration files which can lead to denial of service.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8131

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into code field of an inventory source.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8130

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with store manipulation privileges can execute arbitrary SQL queries by getting access to the database connection through group instance in email templates.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8129

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting an embedded expression into a translation.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8128

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8127

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to an account with Newsletter Template editing permission could exfiltrate the Admin login data, and reset their password, effectively performing a privilege escalation.

    Published: 5 Nov 2019
    4.9
    Medium

    CVE-2019-8126

    Last Modified: 21 Nov 2024

    An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8125

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x. An authenticated admin user can modify configuration parameters via crafted support configuration. The modification can lead to remote code execution.

    Published: 5 Nov 2019
    4.9
    Medium

    CVE-2019-8124

    Last Modified: 21 Nov 2024

    An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Failure to track admin actions related to design configuration could lead to repudiation attacks.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2019-8123

    Last Modified: 21 Nov 2024

    An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. The logging feature required for effective monitoring did not contain sufficent data to effectively track configuration changes.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8122

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with privileges to create products can craft custom layout update and use import product functionality to enable remote code execution.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-8121

    Last Modified: 21 Nov 2024

    An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8120

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8119

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated admin user with import product privileges can delete files through bulk product import and inject code into XSLT file. The combination of these manipulations can lead to remote code execution.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2019-8118

    Last Modified: 21 Nov 2024

    Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8117

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-8116

    Last Modified: 21 Nov 2024

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can leverage a guest session id value following a successful login to gain access to customer account index page.

    Published: 5 Nov 2019
    4.8
    Medium

    CVE-2019-8115

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8114

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to import features can execute arbitrary code via crafted configuration archive file upload.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2019-8113

    Last Modified: 21 Nov 2024

    Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1 uses cryptographically weak random number generator to brute-force the confirmation code for customer registration.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-8112

    Last Modified: 21 Nov 2024

    A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can bypass the email confirmation mechanism via GET request that captures relevant account data obtained from the POST response related to new user creation.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8111

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage plugin functionality related to email templates to manipulate the interceptor class in a way that allows an attacker to execute arbitrary code.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8110

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage email templates hierarchy to manipulate the interceptor class in a way that allows an attacker to execute arbitrary code.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2011-1459

    Last Modified: 21 Nov 2024

    The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin.

    Published: 5 Nov 2019
    8
    High

    CVE-2019-8109

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2019-8108

    Last Modified: 21 Nov 2024

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation setting for a storefront that leads to insecure authentication and session management.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2019-8107

    Last Modified: 21 Nov 2024

    An arbitrary file deletion vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with export data transfer privileges can craft a request to perform arbitrary file deletion.

    Published: 5 Nov 2019