Known Vulnerabilities for products from OpenMage

Listed below are 16 of the newest known vulnerabilities associated with the vendor "OpenMage".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-40488 json Not Provided 2026-04-20 2026-04-20
CVE-2026-25525 json Not Provided 2026-04-20 2026-04-20
CVE-2026-25524 json Not Provided 2026-04-20 2026-04-20
CVE-2023-41879 json Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" coo... 7.5 - HIGH 2023-09-11 2023-09-15
CVE-2023-23617 json OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filt... 7.5 - HIGH 2023-01-28 2023-02-07
CVE-2021-41231 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.2 - HIGH 2023-01-27 2023-11-07
CVE-2021-41144 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.8 - HIGH 2023-01-27 2023-11-07
CVE-2021-41143 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.2 - HIGH 2023-01-27 2023-11-07
CVE-2021-39217 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.2 - HIGH 2023-01-27 2023-02-04
CVE-2021-32759 json OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in version... 7.2 - HIGH 2021-08-27 2021-09-01
CVE-2021-32758 json OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML... 7.2 - HIGH 2021-08-27 2021-09-08
CVE-2021-21427 json Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions bef... 7.2 - HIGH 2021-04-21 2021-04-30
CVE-2021-21426 json Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior a... 9.8 - CRITICAL 2021-04-21 2021-04-30
CVE-2021-21395 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 4.3 - MEDIUM 2023-01-27 2023-02-07
CVE-2020-26295 json OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator wi... 7.2 - HIGH 2021-01-21 2021-01-28
CVE-2020-26285 json OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerab... 7.2 - HIGH 2021-01-21 2021-01-28
CVE-2020-26252 json OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerab... 7.2 - HIGH 2021-01-20 2021-01-28
CVE-2020-15244 json In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credent... 7.2 - HIGH 2020-10-21 2021-11-18
CVE-2020-15151 json OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface... 8 - HIGH 2020-08-20 2021-11-18

Known software with vulnerabilities from OpenMage

Type Vendor Product Version
ApplicationOpenmageMagento1.1.1
ApplicationOpenmageOpenmage-