Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
magento magento 2.4.2 vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2021-36021
Magento versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an Improper input validation vulnerability within the CMS page scheduled update feature. An authenticated attacker with administrative privilege coul...
Magento Magento
Magento Magento 2.3.7
Magento Magento 2.4.2
7.2
CVSSv3
CVE-2021-36023
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to ach...
Magento Magento
Magento Magento 2.3.7
Magento Magento 2.4.2
7.2
CVSSv3
CVE-2021-36036
Magento versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gall...
Magento Magento
Magento Magento 2.3.7
Magento Magento 2.4.2
4.2
CVSSv3
CVE-2021-28583
Magento versions 2.4.2 (and previous versions), 2.4.1-p1 (and previous versions) and 2.3.6-p1 (and previous versions) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename formats. Successful exploitation could allow an malicious user to get un...
Magento Magento
Magento Magento 2.3.6
Magento Magento 2.4.1
Magento Magento 2.4.2
7.2
CVSSv3
CVE-2021-28584
Magento versions 2.4.2 (and previous versions), 2.4.1-p1 (and previous versions) and 2.3.6-p1 (and previous versions) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an auth...
Magento Magento
Magento Magento 2.3.6
Magento Magento 2.4.1
Magento Magento 2.4.2
5.3
CVSSv3
CVE-2021-28585
Magento versions 2.4.2 (and previous versions), 2.4.1-p1 (and previous versions) and 2.3.6-p1 (and previous versions) are affected by an Improper input validation vulnerability in the New customer WebAPI.Successful exploitation could allow an malicious user to send unsolicited sp...
Magento Magento
Magento Magento 2.3.6
Magento Magento 2.4.1
Magento Magento 2.4.2
6.5
CVSSv3
CVE-2021-39864
Adobe Commerce versions 2.4.2-p2 (and previous versions), 2.4.3 (and previous versions) and 2.3.7p1 (and previous versions) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to ...
Adobe Commerce 2.3.7
Adobe Commerce
Adobe Commerce 2.4.2
Adobe Commerce 2.4.3
Adobe Magento Open Source 2.3.7
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
Adobe Magento Open Source 2.4.3
7.2
CVSSv3
CVE-2021-36022
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to ach...
Adobe Magento Open Source
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source 2.4.2
7.2
CVSSv3
CVE-2021-36042
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestrict...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
6.5
CVSSv3
CVE-2021-36012
Magento Commerce versions 2.4.2 (and previous versions), 2.4.2-p1 (and previous versions) and 2.3.7 (and previous versions) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of a...
Adobe Adobe Commerce
Adobe Adobe Commerce 2.4.2
Adobe Magento Open Source
Adobe Magento Open Source 2.4.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »