Severity: CRITICAL (CVSS 9.8)
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Published: 2020-07-22
Last Modified: 2026-06-17
References: