vciy

CVEs we hold for Openmage

Records whose assigning authority named Openmage as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-42458Magento LTS: Reflected XSS - Import -> Data Flow (profiles)OpenMage magento-lts
CVE-2026-42207Magento LTS: Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` - magento-ltsOpenMage magento-lts
CVE-2026-42155Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived InputsOpenMage magento-lts
CVE-2026-40488OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code ExecutionOpenMage magento-lts
CVE-2026-40098OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and…OpenMage magento-lts
CVE-2026-25525OpenMage LTS has Path Traversal Filter Bypass in Dataflow ModuleOpenMage magento-lts
CVE-2026-25524OpenMage LTS's Phar Deserialization leads to Remote Code ExecutionOpenMage magento-lts
CVE-2026-25523Magento's X-Original-Url header can expose admin urlOpenMage magento-lts
CVE-2025-64174OpenMage is vulnerable to XSS in Admin NotificationsOpenMage magento-lts
CVE-2025-27400Magento vulnerable to stored XSS in theme config fieldsOpenMage magento-lts
CVE-2024-41676Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configsOpenMage magento-lts
CVE-2023-41879Magento LTS's guest order "protect code" can be brute-forced too easilyOpenMage magento-lts
CVE-2023-23617OpenMage LTS has DoS vulnerability in MaliciousCode filterOpenMage magento-lts
CVE-2021-41231OpenMage LTS DataFlow upload remote code execution vulnerabilityOpenMage magento-lts
CVE-2021-41144OpenMage LTS authenticated remote code execution through layout updateOpenMage magento-lts
CVE-2021-41143OpenMage LTS arbitrary file deletion in customer media allows for remote code executionOpenMage magento-lts
CVE-2021-39217OpenMage LTS arbitrary command execution in custom layout update through blocksOpenMage magento-lts
CVE-2021-32759Data Flow Sanitation Issue FixOpenMage magento-lts
CVE-2021-32758Layout XML Arbitrary Code FixOpenMage magento-lts
CVE-2021-21427Backport for CVE-2021-21024 Blind SQLi from Magento 2OpenMage magento-lts
CVE-2021-21426Fixes a bug in Zend Framework's Stream HTTP WrapperOpenMage magento-lts
CVE-2021-21395Magneto-lts vulnerable to Cross-Site Request ForgeryOpenMage magento-lts
CVE-2020-26295CMS Editor code executionOpenMage magento-lts
CVE-2020-26285Widget instances allows a hacker to inject an executable file on the server on OpenMageOpenMage magento-lts
CVE-2020-26252Layout XML RCE Vulnerability in OpenMageOpenMage magento-lts
CVE-2020-15244RCE in MagentoOpenMage magento-lts
CVE-2020-15151Observable Timing Discrepancy in OpenMage LTSOpenMage magento-lts

27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.