CVE-2019-7851: Magento
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.
Affected products
- Magento Magento: from 2.1.0, before 2.1.18 (fixed in 2.1.18); from 2.2.0, before 2.2.9 (fixed in 2.2.9); from 2.3.0, before 2.3.2 (fixed in 2.3.2)
Published 2019-08-02. Last modified 2026-06-17.