Openmage

Magento

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 06.11.2025 20:45:55
  • Zuletzt bearbeitet 04.02.2026 21:12:04

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin n...

  • EPSS 0.67%
  • Veröffentlicht 29.07.2024 15:15:16
  • Zuletzt bearbeitet 21.11.2024 09:32:57

Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are inten...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 11.09.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 08:21:50

Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent ...

  • EPSS 0.27%
  • Veröffentlicht 28.01.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:46:32

OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds.

  • EPSS 0.99%
  • Veröffentlicht 27.01.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 06:25:50

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and ...

  • EPSS 1.22%
  • Veröffentlicht 27.01.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:34

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4.22 and 20.0.19 contain a patch for this issue.

  • EPSS 0.6%
  • Veröffentlicht 27.01.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:35

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20.0.19 contain a patch for this issue.

  • EPSS 0.89%
  • Veröffentlicht 27.01.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:55

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 27.01.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:48:16

Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior to 19.4.22 and 20.0.19 are vulnerable to Cross-Site Request Forgery. The password reset form is vulnerable to CSRF between the ti...

  • EPSS 0.55%
  • Veröffentlicht 27.08.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:40

OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage ...