Vulnerabilities > Magento > Magento > 1.3.2.4

DATE CVE VULNERABILITY TITLE RISK
2021-06-28 CVE-2021-28585 Improper Input Validation vulnerability in Magento
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper input validation vulnerability in the New customer WebAPI.Successful exploitation could allow an attacker to send unsolicited spam e-mails.
network
low complexity
magento CWE-20
5.0
2021-02-11 CVE-2021-21029 Cross-site Scripting vulnerability in Magento
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter.
network
magento CWE-79
3.5
2021-02-11 CVE-2021-21022 Authorization Bypass Through User-Controlled Key vulnerability in Magento
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in the product module.
network
low complexity
magento CWE-639
5.3
2021-02-11 CVE-2021-21019 XML Injection (aka Blind XPath Injection) vulnerability in Magento
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module.
network
low complexity
magento CWE-91
critical
9.1
2020-11-09 CVE-2020-24407 Unrestricted Upload of File with Dangerous Type vulnerability in Magento
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution.
network
low complexity
magento CWE-434
critical
9.0
2020-11-09 CVE-2020-24406 Path Traversal vulnerability in Magento
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments.
network
magento CWE-22
4.3
2020-11-09 CVE-2020-24405 Unspecified vulnerability in Magento
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module.
network
low complexity
magento
4.3
2020-11-09 CVE-2020-24404 Unspecified vulnerability in Magento
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component.
network
low complexity
magento
2.7
2020-11-09 CVE-2020-24403 Unspecified vulnerability in Magento
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component.
network
low complexity
magento
2.7
2020-11-09 CVE-2020-24402 Incorrect Default Permissions vulnerability in Magento
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component.
network
low complexity
magento CWE-276
5.5