Amasty develops extensions and modules for Magento e-commerce platforms, with its vulnerability profile centered on the Blog Pro product and recurrent input-handling issues in web page generation contexts such as cross-site scripting. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amasty over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35501MEDIUM Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function. | Nov 23, 2022 | 5.4 | 23 | NO | NO |
CVE-2022-36433MEDIUM The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to | Nov 29, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-35500MEDIUM Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality. | Nov 23, 2022 | 5.4 | 22 | NO | NO |
CVE-2022-36432MEDIUM The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users | Nov 17, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amasty.
Media articles that mention a CVE ID that affects a product developed by Amasty — matched by CVE ID, not by vendor name.