VendorsOpenmagemagentoany version
Vulnerabilities

Openmage Magento 19.4.0 Lts Edition any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2021-21426
Fixes a bug in Zend Framework's Stream HTTP Wrapper
Published 2021-04-21 · Modified
9.8EPSS 0.012
CVE-2021-21427
Backport for CVE-2021-21024 Blind SQLi from Magento 2
Published 2021-04-21 · Modified
9.1EPSS 0.011
CVE-2021-41144
OpenMage LTS authenticated remote code execution through layout update
Published 2023-01-27 · Modified
8.8EPSS 0.012
CVE-2026-40488
OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution
Published 2026-04-20 · Analyzed
8.8EPSS 0.010
CVE-2026-25524
OpenMage LTS's Phar Deserialization leads to Remote Code Execution
Published 2026-04-20 · Analyzed
8.1EPSS 0.007
CVE-2020-15244
RCE in Magento
Published 2020-10-21 · Modified
8.0EPSS 0.013
CVE-2023-41879
Magento LTS's guest order "protect code" can be brute-forced too easily
Published 2023-09-11 · Modified
7.5EPSS 0.013
CVE-2023-23617
OpenMage LTS has DoS vulnerability in MaliciousCode filter
Published 2023-01-27 · Modified
7.5EPSS 0.010
CVE-2021-32759
Data Flow Sanitation Issue Fix
Published 2021-08-27 · Modified
7.2EPSS 0.013
CVE-2021-39217
OpenMage LTS arbitrary command execution in custom layout update through blocks
Published 2023-01-27 · Modified
7.2EPSS 0.013
CVE-2021-41143
OpenMage LTS arbitrary file deletion in customer media allows for remote code execution
Published 2023-01-27 · Modified
7.2EPSS 0.013
CVE-2021-41231
OpenMage LTS DataFlow upload remote code execution vulnerability
Published 2023-01-27 · Modified
7.2EPSS 0.012
CVE-2026-40098
OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant
Published 2026-04-20 · Analyzed
5.4EPSS 0.002
CVE-2026-25523
Magento's X-Original-Url header can expose admin url
Published 2026-02-04 · Analyzed
5.3EPSS 0.004
CVE-2026-25525
OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module
Published 2026-04-20 · Analyzed
4.9EPSS 0.007
CVE-2024-41676
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Published 2024-07-29 · Modified
4.8EPSS 0.004
CVE-2025-64174
OpenMage is vulnerable to XSS in Admin Notifications
Published 2025-11-06 · Analyzed
4.8EPSS 0.002
CVE-2021-21395
Magneto-lts vulnerable to Cross-Site Request Forgery
Published 2023-01-27 · Modified
4.3EPSS 0.004