Products: 3
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-53787

    Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload

    Last Modified: Jun 13, 2026
    Published: Jun 12, 2026

    CVE-2022-36433

    The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.

    Last Modified: Apr 25, 2025
    Published: Nov 29, 2022

    CVE-2022-35500

    Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.

    Last Modified: Apr 28, 2025
    Published: Nov 23, 2022

    CVE-2022-35501

    Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.

    Last Modified: Apr 28, 2025
    Published: Nov 23, 2022

    CVE-2022-36432

    The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.

    Last Modified: Apr 30, 2025
    Published: Nov 17, 2022
    Items Per Page
    Amasty Vulnerabilities & Security CVEs | CVE-DB