Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Magento HIGH 8.8
CVE-2026-40488

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Fix: 20.17.0+
Fix from $1,950 2026-04-20
Magento MEDIUM 5.4
CVE-2026-40098

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Fix: 20.17.0+
Fix from $1,600 2026-04-20
Magento HIGH 8.1
CVE-2026-25524

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Fix: 20.17.0+
Fix from $1,950 2026-04-20
Magento MEDIUM 5.3
CVE-2026-25523

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without p…

Fix: after 20.16.0
Fix from $1,600 2026-02-04
Magento HIGH 7.5
CVE-2023-41879

Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the o…

Fix: 19.5.1 / 20.1.1+
Fix from $1,950 2023-09-11
Magento HIGH 7.5
CVE-2023-23617

OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-28
Magento HIGH 7.2
CVE-2021-41231

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Magento HIGH 8.8
CVE-2021-41144

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remot…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Magento HIGH 7.2
CVE-2021-41143

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute co…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Magento HIGH 7.2
CVE-2021-39217

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via bl…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Magento HIGH 7.2
CVE-2021-32759

OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 2…

Fix: 19.4.13 / 20.0.11+
Fix from $1,950 2021-08-27
Openmage HIGH 7.2
CVE-2021-32758

OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to …

Fix: 19.4.15 / 20.0.11+
Fix from $1,950 2021-08-27
Magento HIGH 7.2
CVE-2021-21427

Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 p…

Fix: 19.4.13 / 20.0.9+
Fix from $1,950 2021-04-21
Magento CRITICAL 9.8
CVE-2021-21426

Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, the…

Fix: 19.4.13 / 20.0.9+
Fix from $2,300 2021-04-21
Openmage HIGH 7.2
CVE-2020-26285

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remo…

Fix: 19.4.10 / 20.0.5+
Fix from $1,950 2021-01-21
Openmage HIGH 7.2
CVE-2020-26295

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/…

Fix: 19.4.10 / 20.0.5+
Fix from $1,950 2021-01-21
Openmage HIGH 7.2
CVE-2020-26252

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remo…

Fix: 19.4.10 / 20.0.6+
Fix from $1,950 2021-01-20
Magento HIGH 7.2
CVE-2020-15244

In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to…

Fix: 20.0.4+
Fix from $1,950 2020-10-21
Openmage Long Term Support HIGH 8.0
CVE-2020-15151

OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attac…

Fix: 19.4.6 / 20.0.2+
Fix from $1,950 2020-08-20