Magento Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2020-9664
Magento versions 1.14.4.5 and earlier and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.