VYPR

Packagist (Composer) package

magento/community-edition

pkg:composer/magento/community-edition

Vulnerabilities (355)

  • CVE-2025-24411HigFeb 11, 2025
    affected >= 2.4.7-beta1, < 2.4.7-p4fixed 2.4.7-p4

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measur

  • CVE-2025-24410HigFeb 11, 2025
    affected >= 2.4.7-beta1, < 2.4.7-p4fixed 2.4.7-p4

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScr

  • CVE-2025-24409HigFeb 11, 2025
    affected >= 2.4.7-beta1, < 2.4.7-p4fixed 2.4.7-p4

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain u

  • CVE-2025-24408MedFeb 11, 2025
    affected >= 2.4.7-beta1, < 2.4.7-p4fixed 2.4.7-p4

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitati

  • CVE-2025-24406HigFeb 11, 2025
    affected >= 2.4.7-beta1, < 2.4.7-p4fixed 2.4.7-p4

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An unauthenticated attacker coul

  • CVE-2024-45149LowOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have a

  • CVE-2024-45135LowOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security measures and have a low impa

  • CVE-2024-45134LowOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may

  • CVE-2024-45133LowOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may

  • CVE-2024-45132MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect confid

  • CVE-2024-45131MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a l

  • CVE-2024-45130MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a

  • CVE-2024-45129MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low i

  • CVE-2024-45128MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a l

  • CVE-2024-45127MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in

  • CVE-2024-45125MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to have a low impact on integrity. Explo

  • CVE-2024-45124MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have a low impact on

  • CVE-2024-45123MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed

  • CVE-2024-45122MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a

  • CVE-2024-45121MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a

Page 3 of 18