CVE-2014-1634: Magento Advanced Newsletter

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.

Affected products

  • Magento Advanced Newsletter: before 2.3.5 (fixed in 2.3.5)

Published 2020-03-09. Last modified 2026-06-17.