VYPR
Critical severity9.8NVD Advisory· Published Jul 22, 2020· Updated Jun 17, 2026

CVE-2020-9664

CVE-2020-9664

Description

Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/corePackagist
<= 1.9.4.5

Affected products

4
  • Magento/Magento2 versions
    cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*+ 1 more
    • cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*range: <=1.14.4.5
    • cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*range: <=1.9.4.5
  • ghsa-coords
    Range: <= 1.9.4.5
  • Range: 1.14.4.5 and earlier, and 1.9.4.5 and earlier versions

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.