Magento Community Edition Improper Input Validation vulnerability
Affected range
ECOSYSTEM: introduced 0; last affected 2.4.5-p14ECOSYSTEM: introduced 2.4.6-p1; last affected 2.4.6-p12ECOSYSTEM: introduced 2.4.9-alpha1; last affected 2.4.9-alpha2ECOSYSTEM: introduced 2.4.7-beta1; last affected 2.4.7-p7ECOSYSTEM: introduced 2.4.8-beta1; last affected 2.4.8-p2
Magento improper input validation vulnerability
Affected range
ECOSYSTEM: introduced 2.3.3-p1; fixed 2.3.7-p3ECOSYSTEM: introduced 2.4.0; fixed 2.4.3-p2
Fixed versions: 2.3.7-p3, 2.4.3-p2
Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
Affected range
ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p6ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p8ECOSYSTEM: introduced 0; fixed 2.4.4-p9
Fixed versions: 2.4.6-p6, 2.4.5-p8, 2.4.4-p9
Magento XML Injection vulnerability in the Widgets Module
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.7-p4ECOSYSTEM: introduced 2.4.4; fixed 2.4.5ECOSYSTEM: introduced 2.4.0; fixed 2.4.3-p3
Fixed versions: 2.3.7-p4, 2.4.5, 2.4.3-p3
Magento executes code via the API File Option Upload Extension
Affected range
ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2ECOSYSTEM: introduced 0; fixed 2.3.7-p1
Fixed versions: 2.4.2-p2, 2.3.7-p1
Magento has an XML Injection vulnerability
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2
Fixed versions: 2.3.7-p1, 2.4.2-p2
Magento is affected by an improper input validation vulnerability while saving a customer's details
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2
Fixed versions: 2.3.7-p1, 2.4.2-p2
Magento has a file extension restrictions bypass
Affected range
ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2ECOSYSTEM: introduced 0; fixed 2.3.7-p1
Fixed versions: 2.4.2-p2, 2.3.7-p1
Magento XML Injection vulnerability in the Widgets Module
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2
Fixed versions: 2.3.7-p1, 2.4.2-p2
Magento affected by remote code execution vulnerability in the CMS page scheduled update feature
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2
Fixed versions: 2.3.7-p1, 2.4.2-p2
Magento improper access control vulnerability within Magento's Media Gallery Upload workflow
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2
Fixed versions: 2.3.7-p1, 2.4.2-p2
Magento XML Injection vulnerability in the Widgets Update Layout
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.7-p1ECOSYSTEM: introduced 2.4.2-p1; fixed 2.4.2-p2
Fixed versions: 2.3.7-p1, 2.4.2-p2
Magneto contains stored XSS vulnerability
Affected range
ECOSYSTEM: introduced 2.4.8-beta1; fixed 2.4.8-p1ECOSYSTEM: introduced 2.4.7-beta1; fixed 2.4.7-p6ECOSYSTEM: introduced 0; fixed 2.4.5-p13ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p11
Fixed versions: 2.4.8-p1, 2.4.7-p6, 2.4.5-p13, 2.4.6-p11
Magento Open Source allows OS Command Injection
Affected range
ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p4ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p6ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p7
Fixed versions: 2.4.6-p4, 2.4.5-p6, 2.4.4-p7
Magento Open Source allows Cross-Site Scripting (XSS)
Affected range
ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p4ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p6ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p7
Fixed versions: 2.4.6-p4, 2.4.5-p6, 2.4.4-p7
Magento Open Source allows Improper Input Validation
Affected range
ECOSYSTEM: introduced 2.4.7-beta1; fixed 2.4.7ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p5ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p7ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p8
Fixed versions: 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
Magento Open Source allows Improper Neutralization of Special Elements Used
Affected range
ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p2ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p4ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p5
Fixed versions: 2.4.6-p2, 2.4.5-p4, 2.4.4-p5
Magento Open Source allows Improper Neutralization of Special Elements Used
Affected range
ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p3ECOSYSTEM: introduced 2.4.4-p1; fixed 2.4.4-p4
Fixed versions: 2.4.5-p3, 2.4.4-p4
Magento Open Source allows Stored Cross-Site Scripting (Stored XSS)
Affected range
ECOSYSTEM: introduced 2.4.3-p1; last affected 2.4.3-p3
Improper Authorization vulnerability in Magento and Adobe Commerce
Affected range
ECOSYSTEM: introduced 2.4.8-beta1; fixed 2.4.8-beta2ECOSYSTEM: introduced 2.4.7-beta1; fixed 2.4.7-p4ECOSYSTEM: introduced 2.4.6-p1; fixed 2.4.6-p9ECOSYSTEM: introduced 2.4.5-p1; fixed 2.4.5-p11ECOSYSTEM: introduced 0; fixed 2.4.4-p12
Fixed versions: 2.4.8-beta2, 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12
Magento vulnerable to a file upload restriction bypass
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.6-p1ECOSYSTEM: introduced 2.4.0; fixed 2.4.2
Fixed versions: 2.3.6-p1, 2.4.2
Magento OS command injection via the WebAPI
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.6-p1ECOSYSTEM: introduced 2.4.0; fixed 2.4.2
Fixed versions: 2.3.6-p1, 2.4.2
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.6-p1ECOSYSTEM: introduced 2.4.0; fixed 2.4.1-p1
Fixed versions: 2.3.6-p1, 2.4.1-p1
Magento 2 Community Edition RCE via Unsafe File Upload
Affected range
ECOSYSTEM: introduced 0; fixed 2.4.1
Fixed versions: 2.4.1
Magento DOM-based Cross-site scripting vulnerability
Affected range
ECOSYSTEM: introduced 0; fixed 2.3.5-p2
Fixed versions: 2.3.5-p2
Show 75 more advisories
GHSA-5gmh-85x8-5cx7 Magento remote code execution (RCE), Cross-Site Scripting (XSS) and other vulnerabilities GHSA-6wm4-3rjj-c8xx Magento Security enhancements that help close RCE,XSS,CSRF and other vulnerabilities GHSA-36xq-7w8w-xp68 Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension GHSA-qmq6-jpvg-j547 Magento is affected by an os command injection via the Data collection endpoint GHSA-7w95-qwhh-q9p3 Magento Path Traversal vulnerability via the `theme[preview_image]` parameter GHSA-7hrj-3c9x-xv5h Magento has incorrect authorization issue that leads to arbitrary file system read