Known Vulnerabilities for products from OpenMage
Listed below are 16 of the newest known vulnerabilities associated with the vendor "OpenMage".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40488 json | Not Provided | 2026-04-20 | 2026-04-20 | |
| CVE-2026-25525 json | Not Provided | 2026-04-20 | 2026-04-20 | |
| CVE-2026-25524 json | Not Provided | 2026-04-20 | 2026-04-20 | |
| CVE-2023-41879 json | Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" coo... | 7.5 - HIGH | 2023-09-11 | 2023-09-15 |
| CVE-2023-23617 json | OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filt... | 7.5 - HIGH | 2023-01-28 | 2023-02-07 |
| CVE-2021-41231 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2023-01-27 | 2023-11-07 |
| CVE-2021-41144 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-01-27 | 2023-11-07 |
| CVE-2021-41143 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2023-01-27 | 2023-11-07 |
| CVE-2021-39217 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2023-01-27 | 2023-02-04 |
| CVE-2021-32759 json | OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in version... | 7.2 - HIGH | 2021-08-27 | 2021-09-01 |
| CVE-2021-32758 json | OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML... | 7.2 - HIGH | 2021-08-27 | 2021-09-08 |
| CVE-2021-21427 json | Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions bef... | 7.2 - HIGH | 2021-04-21 | 2021-04-30 |
| CVE-2021-21426 json | Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior a... | 9.8 - CRITICAL | 2021-04-21 | 2021-04-30 |
| CVE-2021-21395 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.3 - MEDIUM | 2023-01-27 | 2023-02-07 |
| CVE-2020-26295 json | OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator wi... | 7.2 - HIGH | 2021-01-21 | 2021-01-28 |
| CVE-2020-26285 json | OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerab... | 7.2 - HIGH | 2021-01-21 | 2021-01-28 |
| CVE-2020-26252 json | OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerab... | 7.2 - HIGH | 2021-01-20 | 2021-01-28 |
| CVE-2020-15244 json | In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credent... | 7.2 - HIGH | 2020-10-21 | 2021-11-18 |
| CVE-2020-15151 json | OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface... | 8 - HIGH | 2020-08-20 | 2021-11-18 |