magento/community-edition
Magento 2 (Open Source)
Security Advisories for magento/community-edition in packagist
High
over 1 year ago
Magento Open Source allows Improper Input Validation
packagist
magento/project-community-edition, magento/community-edition
High
almost 2 years ago
Magento Open Source allows OS Command Injection
packagist
magento/project-community-edition, magento/community-edition
High
almost 2 years ago
Magento Open Source allows Cross-Site Scripting (XSS)
packagist
magento/project-community-edition, magento/community-edition
Moderate
almost 2 years ago
Magento Open Source allows Cross-Site Request Forgery (CSRF)
packagist
magento/project-community-edition, magento/community-edition
Moderate
almost 2 years ago
Magento Open Source allows Uncontrolled Resource Consumption
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source allows SQL Injection
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source allows SQL Injection
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source allows Uncontrolled Resource Consumption
packagist
magento/community-edition
Moderate
about 2 years ago
Magento Open Source allows Improper Authorization
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source allows Server-Side Request Forgery (SSRF)
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source allows Incorrect Authorization
packagist
magento/project-community-edition, magento/community-edition
Low
about 2 years ago
Magento Open Source allows Cross-Site Scripting (XSS)
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source has Improper Input Validation Vulnerability
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source allows SQL Injection
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 2 years ago
Magento Open Source affected by Improper Input Validation
packagist
magento/project-community-edition, magento/community-edition
Critical
about 2 years ago
Magento XML Injection vulnerability in the Widgets Update Layout
packagist
magento/community-edition, magento/project-community-edition
Critical
about 2 years ago
Magento improper access control vulnerability within Magento's Media Gallery Upload workflow
packagist
magento/community-edition, magento/project-community-edition
Critical
about 2 years ago
Magento affected by remote code execution vulnerability in the CMS page scheduled update feature
packagist
magento/community-edition, magento/project-community-edition
High
over 2 years ago
Magento Open Source allows Improper Neutralization of Special Elements Used
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Incorrect Authorization
packagist
magento/project-community-edition, magento/community-edition
Low
over 2 years ago
Magento Open Source allows Cross-Site Scripting (XSS)
packagist
magento/community-edition
Low
over 2 years ago
Magento Open Source allows Incorrect Authorization
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Incorrect Authorization
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows XML Injection
packagist
magento/project-community-edition, magento/community-edition
Low
over 2 years ago
Magento Open Source affected by Improper Input Validation
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Server-Side Request Forgery (SSRF)
packagist
magento/project-community-edition, magento/community-edition
Low
over 2 years ago
Magento Open Source has Business Logic Errors Vulnerability
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Incorrect Authorization
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Server-Side Request Forgery (SSRF)
packagist
magento/project-community-edition, magento/community-edition
High
over 2 years ago
Magento Open Source allows Improper Neutralization of Special Elements Used
packagist
magento/project-community-edition, magento/community-edition
Low
over 2 years ago
Magento Open Source allows Incorrect Authorization
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source affected by Improper Input Validation
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Information Exposure
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Incorrect Authorization
packagist
magento/project-community-edition, magento/community-edition
High
over 2 years ago
Magento Open Source allows XML Injection
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 2 years ago
Magento Open Source allows Improper Access Control
packagist
magento/community-edition
High
about 3 years ago
Magento Improper input validation vulnerability
packagist
magento/community-edition
High
about 3 years ago
Magento Open Source allows Stored Cross-Site Scripting (Stored XSS)
packagist
magento/project-community-edition, magento/community-edition
Moderate
about 3 years ago
Magento Open Source allows Improper Access Control
packagist
magento/project-community-edition, magento/community-edition
Moderate
over 3 years ago
Magento Open Source has Improper Access Control vulnerability
packagist
magento/community-edition, magento/project-community-edition
Moderate
over 3 years ago
Magento stored Cross-Site Scripting (XSS) vulnerability
packagist
magento/community-edition
High
over 3 years ago
Magento Improper Access Control vulnerability
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Improper Access Control vulnerability
packagist
magento/community-edition
High
over 3 years ago
Magento Improper Authorization vulnerability
packagist
magento/community-edition
Moderate
over 3 years ago
Magento stored Cross-Site Scripting (XSS) vulnerability
packagist
magento/community-edition
Critical
over 3 years ago
Magento XML Injection vulnerability in the Widgets Module
packagist
magento/community-edition
Moderate
over 3 years ago
Magento stored cross-site scripting vulnerability
packagist
magento/community-edition, magento/project-community-edition
Moderate
over 3 years ago
Magento stored cross-site scripting vulnerability in the customer address upload feature
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento remote code execution vulnerability
packagist
magento/community-edition
Critical
over 3 years ago
Magento Broken authentication and session managememt
packagist
magento/community-edition
Critical
over 3 years ago
Magento 2 Community Edition SQLi Vulnerability
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Open Source allows Cross-Site Request Forgery (CSRF)
packagist
magento/project-community-edition, magento/community-edition
Low
over 3 years ago
Magento Information Disclosure vulnerability
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Improper Authorization vulnerability in the customers module
packagist
magento/community-edition
High
over 3 years ago
Magento XML Injection vulnerability in the Widgets Update Layout
packagist
magento/community-edition, magento/project-community-edition
Moderate
over 3 years ago
Magento affected by a business logic error in the placeOrder graphql mutation
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento XML Injection vulnerability in the 'City' field
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento improper authorization vulnerability
packagist
magento/community-edition, magento/project-community-edition
Critical
over 3 years ago
Magento is affected by an improper input validation vulnerability while saving a customer's details
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento Path Traversal vulnerability via the `theme[preview_image]` parameter
packagist
magento/community-edition, magento/project-community-edition
Critical
over 3 years ago
Magento has an XML Injection vulnerability
packagist
magento/community-edition, magento/project-community-edition
Critical
over 3 years ago
Magento XML Injection vulnerability in the Widgets Module
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento is affected by an os command injection via the Data collection endpoint
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento allows attackers to alter the price of items
packagist
magento/community-edition, magento/project-community-edition
Critical
over 3 years ago
Magento executes code via the API File Option Upload Extension
packagist
magento/community-edition, magento/project-community-edition
Moderate
over 3 years ago
Magento discloses sensitive information
packagist
magento/community-edition, magento/project-community-edition
Moderate
over 3 years ago
Magento discloses sensitive information via the Multishipping Module
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento affected by remote code execution via a file upload
packagist
magento/community-edition, magento/project-community-edition
Moderate
over 3 years ago
Magento is affected by an improper authorization vulnerability
packagist
magento/community-edition, magento/project-community-edition
Critical
over 3 years ago
Magento has a file extension restrictions bypass
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento vulnerable to file upload attack
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento affected by a server-side denial-of-service using a GraphQL field
packagist
magento/community-edition, magento/project-community-edition
High
over 3 years ago
Magento Violation of Secure Design Principles vulnerability in RMA PDF filename formats
packagist
magento/community-edition
Moderate
over 3 years ago
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Unauthorized access to restricted resources
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Improper input validation vulnerability
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Insufficient Session Expiration
packagist
magento/community-edition
Moderate
over 3 years ago
Magento stored cross-site scripting vulnerability in the admin console
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Insecure Direct Object Reference (IDOR) in the product module
packagist
magento/community-edition
Moderate
over 3 years ago
Magento improper authorization vulnerability in the integrations module
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Insufficient Session Expiration
packagist
magento/community-edition
Critical
over 3 years ago
Magento Blind SQL Injection in the Search module
packagist
magento/community-edition
Moderate
over 3 years ago
Magento Reflected Cross-site Scripting vulnerability via 'file' parameter
packagist
magento/community-edition
Critical
over 3 years ago
Magento XML injection in the Widgets module
packagist
magento/community-edition
High
over 3 years ago
Magento stored cross-site scripting (XSS) in the customer address upload feature
packagist
magento/community-edition
Moderate
over 3 years ago
Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API
packagist
magento/community-edition
Critical
over 3 years ago
Magento vulnerable to a file upload restriction bypass
packagist
magento/community-edition
High
over 3 years ago
Magento OS command injection via the customer attribute save controller
packagist
magento/community-edition
Critical
over 3 years ago
Magento OS command injection via the WebAPI
packagist
magento/community-edition
Low
over 3 years ago
Magento information disclosure vulnerability
packagist
magento/community-edition
Moderate
over 3 years ago
Magento incorrect permissions vulnerability in the Inventory module
packagist
magento/community-edition
Critical
over 3 years ago
Magento 2 Community Edition RCE via Unsafe File Upload
packagist
magento/community-edition
Low
over 3 years ago
Magento incorrect user permissions vulnerability within the Inventory component
packagist
magento/community-edition