CVE-2021-21019
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 3.01%
- CWE
- CWE-91
- Published
- 2021-02-11
- Last modified
- 2026-03-13
Affected products
- Adobe Magento Commerce
Weakness type
Related vulnerabilities
- CVE-2023-46214 — Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
- CVE-2022-34253 — Adobe Commerce XML Injection Arbitrary code execution
- CVE-2021-36020 — Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution
- CVE-2021-36033 — Magento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2021-36028 — Magento Commerce XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2020-8479 — ABB Central Licensing System - XML External Entity Injection
- CVE-2021-21025 — Magento Commerce XML Injection Could Lead To Arbitrary Code Execution
- CVE-2021-39181 — Unsafe Deserialization of User Data Using XStream