Openmage

Magento

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.08%
  • Veröffentlicht 20.04.2026 16:23:07
  • Zuletzt bearbeitet 23.04.2026 17:45:16

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option f...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.04.2026 16:19:55
  • Zuletzt bearbeitet 23.04.2026 17:46:42

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the shared wishlist add-to-...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 20.04.2026 16:14:14
  • Zuletzt bearbeitet 23.04.2026 17:47:02

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the Dataflow module in Open...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 20.04.2026 16:11:16
  • Zuletzt bearbeitet 23.04.2026 17:47:24

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `geti...

  • EPSS 0.01%
  • Veröffentlicht 04.02.2026 21:21:56
  • Zuletzt bearbeitet 20.02.2026 20:57:08

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 06.11.2025 20:45:55
  • Zuletzt bearbeitet 04.02.2026 21:12:04

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin n...

  • EPSS 0.67%
  • Veröffentlicht 29.07.2024 15:15:16
  • Zuletzt bearbeitet 21.11.2024 09:32:57

Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are inten...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 11.09.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 08:21:50

Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent ...

  • EPSS 0.27%
  • Veröffentlicht 28.01.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:46:32

OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds.

  • EPSS 0.99%
  • Veröffentlicht 27.01.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 06:25:50

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and ...