In Magento versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9, and earlier a medium severity vulnerability CVE-2024-39416 was detected. This vulnerability allows low-privileged attackers to bypass security features and disclose minor information without requiring user interaction. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-39416.
Read more E-commerceIn Prestashop v.8.1.7 and earlier a critical severity vulnerability CVE-2024-41651 was detected. It allows a remote attacker to run arbitrary code through the module upgrade feature. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-41651.
Read more E-commerceIn WooCommerce versions before 3.5.1 a medium severity vulnerability CVE-2024-43128 was detected. This vulnerability allows an attacker to inject malicious code due to insufficient input validation. To fix this issue, users must upgrade to a version later than 3.5.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43128.
Read more E-commerceIn Magento Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier a high severity Server-Side Request Forgery (SSRF) vulnerability CVE-2024-34111 was detected. This vulnerability allows attackers to force the application to make arbitrary requests, potentially leading to arbitrary file system reads. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34111.
Read more E-commerceIn Magento Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier a high severity vulnerability CVE-2024-34108 was detected. This improper input validation vulnerability allows attackers to execute arbitrary code within the context of the current user. Although no user interaction is required for exploitation, admin privileges are needed, and the scope of the attack is changed. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34108.
Read more E-commerceIn Magento versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier a critical severity vulnerability CVE-2024-34107 was detected. This vulnerability relates to improper access control and allows attackers to bypass security measures and view minor unauthorized information. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34107.
Read more E-commerceIn Joomla versions 4.0.0 to 4.4.5 and 5.0.0 to 5.1.1 a medium severity vulnerability CVE-2024-21730 was detected. This vulnerability allows attackers to inject malicious scripts that would be executed in the user’s browser, posing a security risk. To fix this problem, users should upgrade Joomla to versions 4.4.6 and 5.1.2. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-21730.
Read more CMSIn Joomla versions 3.0.0 to 3.10.15, 4.0.0 to 4.4.5, and 5.0.0 to 5.1.1 a medium severity vulnerability CVE-2024-21731 was detected. This vulnerability allows attackers to embed harmful scripts that can run within a user’s web browser, posing significant security risks. To fix this problem, users should upgrade Joomla to versions 3.10.16, 4.4.6, and 5.1.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-21731.
In Magento versions before 20.10.1 a medium severity vulnerability CVE-2024-41676 was detected. This vulnerability allows attackers to view sensitive files in GitLab. To fix this problem, users should upgrade Magento to version 20.10.1 or higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41676.
Read more E-commerce