magento/core
Packagist24 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting magento/corepage 1 of 1
- CVE-2015-6497HIGHCVSS 8.8EG 8.8✓ Fixed in 1.9.2.12020-01-15
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated…
- CVE-2019-8227MEDIUMCVSS 4.8EG 4.8✓ Fixed in 1.9.4.32019-11-06
In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when creating profile action XML.
- CVE-2019-8230HIGHCVSS 7.2EG 7.2✓ Fixed in 1.9.4.32019-11-06
In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute arbitrary code through a crafted support/output path.
- CVE-2019-8231HIGHCVSS 7.2EG 7.2✓ Fixed in 1.9.4.32019-11-06
In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.
- CVE-2020-3715MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.9.4.42020-01-29
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-3719HIGHCVSS 7.5EG 7.5✓ Fixed in 1.9.4.42020-01-29
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-9576CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9577MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure .
- CVE-2020-9578CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9579CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9580CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9581MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-9582CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9583CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9584MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2020-9585CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9587HIGHCVSS 7.5EG 7.5✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.
- CVE-2020-9588HIGHCVSS 7.2EG 7.2✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
- CVE-2020-9591HIGHCVSS 7.5EG 7.5✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin …
- CVE-2020-9630CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.
- CVE-2020-9631CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9632CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.4.52020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9664CRITICALCVSS 9.8EG 9.82020-07-22
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9665MEDIUMCVSS 6.1EG 6.12020-07-22
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Check whether magento/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for magento/core CVEs against the assets you own.
Start Free Scan →