CVEs we hold for Openmage
Records whose assigning authority named Openmage as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-42207Magento LTS: Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` - magento-ltsOpenMage magento-lts
CVE-2026-42155Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived InputsOpenMage magento-lts
CVE-2026-40488OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code ExecutionOpenMage magento-lts
CVE-2026-40098OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and…OpenMage magento-lts
CVE-2026-25524OpenMage LTS's Phar Deserialization leads to Remote Code ExecutionOpenMage magento-lts
CVE-2024-41676Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configsOpenMage magento-lts
CVE-2023-41879Magento LTS's guest order "protect code" can be brute-forced too easilyOpenMage magento-lts
CVE-2021-41144OpenMage LTS authenticated remote code execution through layout updateOpenMage magento-lts
CVE-2021-41143OpenMage LTS arbitrary file deletion in customer media allows for remote code executionOpenMage magento-lts
CVE-2021-39217OpenMage LTS arbitrary command execution in custom layout update through blocksOpenMage magento-lts
CVE-2020-26285Widget instances allows a hacker to inject an executable file on the server on OpenMageOpenMage magento-lts
27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.