AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-8126

MEDIUM · CVSS 4.9 EPSS 0.88%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-11-05 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-8126
Severity
MEDIUM
CVSS
4.9
EPSS
0.88%

Original NVD Description

An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document type definition and XML layout allow processing of external entities which can lead to information disclosure.