Known Vulnerabilities for products from Magmi Project
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Magmi Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-5777 json | MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the ev... | 9.8 - CRITICAL | 2020-09-01 | 2020-09-08 |
| CVE-2020-5776 json | Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible ... | 8.8 - HIGH | 2020-09-01 | 2020-09-08 |
| CVE-2017-7391 json | A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration of use... | Not Provided | 2017-04-01 | 2025-04-20 |
| CVE-2015-2068 json | Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow ... | Not Provided | 2015-02-24 | 2026-05-06 |
| CVE-2015-2067 json | Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Serv... | Not Provided | 2015-02-24 | 2026-05-06 |
| CVE-2014-8770 json | Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and ear... | Not Provided | 2014-11-13 | 2026-05-06 |
Known software with vulnerabilities from Magmi Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Magmi Project | Magmi | - |