CVE-2014-1634: Magento Advanced Newsletter
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.
Affected products
- Magento Advanced Newsletter: before 2.3.5 (fixed in 2.3.5)
Published 2020-03-09. Last modified 2026-06-17.