Vulnerabilities > Magento

DATE CVE VULNERABILITY TITLE RISK
2019-11-06 CVE-2019-8128 Cross-site Scripting vulnerability in Magento
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
network
low complexity
magento CWE-79
5.4
2019-11-05 CVE-2019-8127 SQL Injection vulnerability in Magento
A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
network
low complexity
magento CWE-89
8.8
2019-11-05 CVE-2019-8126 XXE vulnerability in Magento
An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
network
low complexity
magento CWE-611
4.9
2019-11-05 CVE-2019-8125 Unspecified vulnerability in Magento
A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x.
network
low complexity
magento
7.2
2019-11-05 CVE-2019-8124 Unspecified vulnerability in Magento
An insufficient logging and monitoring vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3.
network
low complexity
magento
4.9
2019-11-05 CVE-2019-8123 Unspecified vulnerability in Magento
An insufficient logging and monitoring vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3.
network
low complexity
magento
5.3
2019-11-05 CVE-2019-8122 Unspecified vulnerability in Magento
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3.
network
low complexity
magento
8.8
2019-11-05 CVE-2019-8121 Unspecified vulnerability in Magento
An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3.
network
low complexity
magento
critical
9.8
2019-11-05 CVE-2019-8120 Cross-site Scripting vulnerability in Magento
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3.
network
low complexity
magento CWE-79
5.4
2019-11-05 CVE-2019-8119 Unspecified vulnerability in Magento
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3.
network
low complexity
magento
7.2