vciy

Adobe Magento Commerce: 24 records in one advisory

24 records announced together, published between 2021-09-01 and 2023-09-06, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/magento/apsb21-64.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

17 of 24 records name something of its own. For the other 7, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-20 Improper Input Validation (CWE-20).

What this page does not cover

This batch is 24 of the 26 records that cite the same advisory. The other 2 are different findings announced alongside it.

None of those 2 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2021-36012Magento Commerce Gift Card Business Logic ErrorCWE-840 Business Logic Errors (CWE-840)
CVE-2021-36020Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code ExecutionCWE-91 XML Injection (aka Blind XPath…
CVE-2021-36022Magento Commerce Widgets Update Layout XML Injection Vulnerability Could Lead To Remote Code ExecutionCWE-78 Improper Neutralization of Special…
CVE-2021-36023Magento Commerce Widgets Update Layout XML Injection Vulnerability Could Lead To Remote Code ExecutionCWE-78 Improper Neutralization of Special…
CVE-2021-36024Magento Commerce Improper Neutralization of Special Elements Used In A CommandCWE-78 Improper Neutralization of Special…
CVE-2021-36025Magento Commerce Customer Edition Improper Input Validation Could Lead To Remote Code ExecutionCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36026Magento Commerce Stored Cross-site Scripting VulnerabilityCWE-79 Cross-site Scripting (Stored XSS)…
CVE-2021-36027Magento Commerce Stored Cross-site Scripting VulnerabilityCWE-79 Cross-site Scripting (Stored XSS)…
CVE-2021-36028Magento Commerce XML Injection Vulnerability Could Lead To Remote Code ExecutionCWE-91 XML Injection (aka Blind XPath…
CVE-2021-36029Magento Commerce Improper Authorization Vulnerability Could Lead To Remote Code ExecutionCWE-285 Improper Authorization (CWE-285)
CVE-2021-36030Magento Commerce Improper Input Validation During Checkout Process Could Lead To Privilege EscalationCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36031Magento Commerce Path Traversal In `theme[preview_image]` Parameter Could Lead To Remote Code ExecutionCWE-22 Improper Limitation of a Pathname to a…
CVE-2021-36032Magento Commerce Improper Input Validation Could Lead To Information Exposure and Privilege EscalationCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36033Magento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code ExecutionCWE-91 XML Injection (aka Blind XPath…
CVE-2021-36034Magento Commerce Improper Input Validation Could Lead To Remote Code ExecutionCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36035Magento Commerce Stock Media Improper Input Validation Could Lead To Remote Code ExecutionCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36037Magento Commerce Improper Authorization Vulnerability Could Lead To Information ExposureCWE-285 Improper Authorization (CWE-285)
CVE-2021-36038Magento Commerce Multishipping Module Improper Input Validation Could Lead To Information ExposureCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36039Magento Commerce `quoteId` parameter Incorrect Authorization Vulnerability Could Lead To Information DisclosureCWE-863 Incorrect Authorization (CWE-863)
CVE-2021-36040Magento Commerce Improper Input Validation Could Lead To Remote Code ExecutionCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36041Magento Commerce Improper Input Validation Could Lead To Remote Code ExecutionCWE-20 Improper Input Validation (CWE-20)
CVE-2021-36042Magento Commerce API File Option Upload Extension Improper Input Validation Vulnerability Could Lead To Remote Code…CWE-20 Improper Input Validation (CWE-20)
CVE-2021-36043Magento Commerce Authenticated Blind SSRF Could Lead To Remote Code ExecutionCWE-918 Server-Side Request Forgery (SSRF)…
CVE-2021-36044Magento Commerce GraphQL Improper Input Validation Could Lead To Denial Of ServiceCWE-20 Improper Input Validation (CWE-20)

24 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.