Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-40488 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo… Magento 20.17.0+ Fix from $1,9502026-04-20 MEDIUM 5.4 CVE-2026-40098 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo… Magento 20.17.0+ Fix from $1,6002026-04-20 HIGH 8.1 CVE-2026-25524 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo… Magento 20.17.0+ Fix from $1,9502026-04-20 MEDIUM 5.3 CVE-2026-25523 Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without p… Magento after 20.16.0 Fix from $1,6002026-02-04 HIGH 7.5 CVE-2023-41879 Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the o… Magento 19.5.1 / 20.1.1+ Fix from $1,9502023-09-11 HIGH 7.5 CVE-2023-23617 OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-28 HIGH 7.2 CVE-2021-41231 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 8.8 CVE-2021-41144 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remot… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 7.2 CVE-2021-41143 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute co… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 7.2 CVE-2021-39217 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via bl… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 7.2 CVE-2021-32759 OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 2… Magento 19.4.13 / 20.0.11+ Fix from $1,9502021-08-27 HIGH 7.2 CVE-2021-32758 OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to … Openmage 19.4.15 / 20.0.11+ Fix from $1,9502021-08-27 HIGH 7.2 CVE-2021-21427 Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 p… Magento 19.4.13 / 20.0.9+ Fix from $1,9502021-04-21 CRITICAL 9.8 CVE-2021-21426 Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, the… Magento 19.4.13 / 20.0.9+ Fix from $2,3002021-04-21 HIGH 7.2 CVE-2020-26285 OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remo… Openmage 19.4.10 / 20.0.5+ Fix from $1,9502021-01-21 HIGH 7.2 CVE-2020-26295 OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/… Openmage 19.4.10 / 20.0.5+ Fix from $1,9502021-01-21 HIGH 7.2 CVE-2020-26252 OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remo… Openmage 19.4.10 / 20.0.6+ Fix from $1,9502021-01-20 HIGH 7.2 CVE-2020-15244 In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to… Magento 20.0.4+ Fix from $1,9502020-10-21 HIGH 8.0 CVE-2020-15151 OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attac… Openmage Long Term Support 19.4.6 / 20.0.2+ Fix from $1,9502020-08-20