VYPR

Packagist (Composer) package

magento/community-edition

pkg:composer/magento/community-edition

Vulnerabilities (355)

  • CVE-2024-45120LowOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to alter a condition between th

  • CVE-2024-45119MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary re

  • CVE-2024-45118MedOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have hi

  • CVE-2024-45117HigOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to read files from the system outside of the in

  • CVE-2024-45116HigOct 10, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p3fixed 2.4.7-p3

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially crafted link or submitting a f

  • CVE-2024-39419MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify mi

  • CVE-2024-39418MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures to view and e

  • CVE-2024-39417MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose

  • CVE-2024-39416MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose

  • CVE-2024-39415MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose

  • CVE-2024-39414MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose

  • CVE-2024-39413MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose

  • CVE-2024-39412MedAug 14, 2024
    affected >= 2.4.7-p1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and perform a

  • CVE-2024-39411MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose

  • CVE-2024-39410MedAug 14, 2024
    affected >= 2.4.7-p1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. The vulnerability could b

  • CVE-2024-39409MedAug 14, 2024
    affected >= 2.4.7-p1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. The vulnerability could b

  • CVE-2024-39408MedAug 14, 2024
    affected >= 2.4.7-p1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changeson behalf of a user. The vulnerability could be

  • CVE-2024-39407MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify mi

  • CVE-2024-39406MedAug 14, 2024
    affected >= 2.4.7-p1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerabi

  • CVE-2024-39405MedAug 14, 2024
    affected >= 2.4.7-beta1, < 2.4.7-p2fixed 2.4.7-p2

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify mi

Page 4 of 18