cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2019-8141,https://securityvulnerability.io/vulnerability/CVE-2019-8141,,"A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user with administrative privileges (system level import) can execute arbitrary code through a Phar deserialization vulnerability in the import functionality.",Adobe,Magento 2,7.2,HIGH,0.002360000042244792,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8128,https://securityvulnerability.io/vulnerability/CVE-2019-8128,,"A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.",Adobe,Magento 2,5.4,MEDIUM,0.001180000021122396,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8232,https://securityvulnerability.io/vulnerability/CVE-2019-8232,,"In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated user with administrative privileges for the import feature can execute arbitrary code through a race condition that allows webserver configuration file modification.",Adobe,Magento 1 & 2,6.6,MEDIUM,0.0008800000068731606,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8154,https://securityvulnerability.io/vulnerability/CVE-2019-8154,,"A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file that specifies product design update.",Adobe,Magento 2,8.8,HIGH,0.0023900000378489494,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8147,https://securityvulnerability.io/vulnerability/CVE-2019-8147,,"A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via customer attribute label.",Adobe,Magento 2,5.4,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8150,https://securityvulnerability.io/vulnerability/CVE-2019-8150,,"A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate layouts and images can insert a malicious payload into the page layout.",Adobe,Magento 2,8.8,HIGH,0.0025400000158697367,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8152,https://securityvulnerability.io/vulnerability/CVE-2019-8152,,"A stored cross-site scripting (XSS) vulnerability exists in in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to the wysiwyg editor can abuse the blockDirective() function and inject malicious javascript in the cache of the admin dashboard.",Adobe,Magento 1 & 2,5.4,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8149,https://securityvulnerability.io/vulnerability/CVE-2019-8149,,"Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.",Adobe,Magento 2,9.8,CRITICAL,0.0034600000362843275,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8148,https://securityvulnerability.io/vulnerability/CVE-2019-8148,,A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when creating a content page via page builder.,Adobe,Magento 2,4.8,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8153,https://securityvulnerability.io/vulnerability/CVE-2019-8153,,"A mitigation bypass to prevent cross-site scripting (XSS) exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Successful exploitation of this vulnerability would result in an attacker being able to bypass the `escapeURL()` function and execute a malicious XSS payload.",Adobe,Magento 2,6.1,MEDIUM,0.0007399999885819852,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8233,https://securityvulnerability.io/vulnerability/CVE-2019-8233,,"In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of the sanitization engine ignoring HTML comments.",Adobe,Magento 2,6.1,MEDIUM,0.0011899999808520079,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8151,https://securityvulnerability.io/vulnerability/CVE-2019-8151,,"A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to manipulate shippment settings can execute arbitrary code through server-side request forgery due to unsafe handling of a carrier gateway.",Adobe,Magento 2,7.2,HIGH,0.002360000042244792,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8130,https://securityvulnerability.io/vulnerability/CVE-2019-8130,,"A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with store manipulation privileges can execute arbitrary SQL queries by getting access to the database connection through group instance in email templates.",Adobe,Magento 2,8.8,HIGH,0.000699999975040555,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8131,https://securityvulnerability.io/vulnerability/CVE-2019-8131,,"A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into code field of an inventory source.",Adobe,Magento 2,5.4,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8136,https://securityvulnerability.io/vulnerability/CVE-2019-8136,,"An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.",Adobe,Magento 2,9.8,CRITICAL,0.0024399999529123306,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8133,https://securityvulnerability.io/vulnerability/CVE-2019-8133,,"A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with privileges to generate sitemaps can bypass configuration that restricts directory access. The bypass allows overwrite of a subset of configuration files which can lead to denial of service.",Adobe,Magento 2,6.5,MEDIUM,0.0007800000021234155,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8134,https://securityvulnerability.io/vulnerability/CVE-2019-8134,,"A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A user with marketing privileges can execute arbitrary SQL queries in the database when accessing email template variables.",Adobe,Magento 2,8.8,HIGH,0.000699999975040555,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8135,https://securityvulnerability.io/vulnerability/CVE-2019-8135,,"A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.",Adobe,Magento 2,9.8,CRITICAL,0.0024800000246614218,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8137,https://securityvulnerability.io/vulnerability/CVE-2019-8137,,"A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to manipulate CMS section of the website can trigger remote code execution via custom layout update.",Adobe,Magento 2,8.8,HIGH,0.0024999999441206455,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8138,https://securityvulnerability.io/vulnerability/CVE-2019-8138,,"A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can execute arbitrary JavaScript code by providing arbitrary API endpoint that will not be chcecked by sale pickup event.",Adobe,Magento 2,5.4,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8139,https://securityvulnerability.io/vulnerability/CVE-2019-8139,,A stored cross-site scripting (XSS) vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary Javascript code into the dynamic block when invoking page builder on a product.,Adobe,Magento 2,5.4,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8140,https://securityvulnerability.io/vulnerability/CVE-2019-8140,,"An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to transform uploaded JPEG file into a PHP file.",Adobe,Magento 2,4.9,MEDIUM,0.0008999999845400453,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8142,https://securityvulnerability.io/vulnerability/CVE-2019-8142,,"A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via title of an order when configuring sales payment methods for a store.",Adobe,Magento 2,5.4,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8146,https://securityvulnerability.io/vulnerability/CVE-2019-8146,,"A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code when adding a new customer attribute for stores.",Adobe,Magento 2,5.4,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0 CVE-2019-8143,https://securityvulnerability.io/vulnerability/CVE-2019-8143,,"A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.",Adobe,Magento 2,6.5,MEDIUM,0.0006300000241026282,false,,false,false,false,,,false,false,,2019-11-06T00:15:00.000Z,0