Vulnerabilities > Adobe > Adobe Commerce

DATE CVE VULNERABILITY TITLE RISK
2021-09-01 CVE-2021-36020 XML Injection (aka Blind XPath Injection) vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field.
network
low complexity
adobe CWE-91
critical
9.8
2021-09-01 CVE-2021-36022 XML Injection (aka Blind XPath Injection) vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout.
network
low complexity
adobe CWE-91
7.2
2021-09-01 CVE-2021-36024 Command Injection vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint.
network
low complexity
adobe CWE-77
7.2
2021-09-01 CVE-2021-36025 Unspecified vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file.
network
low complexity
adobe
7.2
2021-09-01 CVE-2021-36026 Unspecified vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe
6.1
2021-09-01 CVE-2021-36027 Unspecified vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe
6.1
2021-09-01 CVE-2021-36028 Unspecified vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product.
network
low complexity
adobe
7.2
2021-09-01 CVE-2021-36029 Unspecified vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability.
network
low complexity
adobe
7.2
2021-09-01 CVE-2021-36030 Unspecified vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process.
network
low complexity
adobe
7.5
2021-09-01 CVE-2021-36032 Authorization Bypass Through User-Controlled Key vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability.
network
low complexity
adobe CWE-639
8.8