Skip to content
Noroxi

OpenMage records

23 published records for vendor openmage.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

23 records
  • Fixes a bug in Zend Framework's Stream HTTP Wrapper

    CriticalCVSS 9.8No exploitEPSS 1%

    openmage · magentoApr 21, 2021

  • OpenMage LTS authenticated remote code execution through layout update

    HighCVSS 8.8No exploitEPSS 1%

    openmage · magentoJan 27, 2023

  • OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution

    HighCVSS 8.7No exploitEPSS 1%

    openmage · magentoApr 20, 2026

  • Observable Timing Discrepancy in OpenMage LTS

    HighCVSS 8.0No exploitEPSS 1%

    openmage · openmage long term supportAug 19, 2020

  • OpenMage LTS's Phar Deserialization leads to Remote Code Execution

    HighCVSS 8.1Proof of conceptEPSS 1%

    openmage · magentoApr 20, 2026

  • Magento LTS's guest order "protect code" can be brute-forced too easily

    HighCVSS 7.5No exploitEPSS 1%

    openmage · magentoSep 11, 2023

  • OpenMage LTS has DoS vulnerability in MaliciousCode filter

    HighCVSS 7.5No exploitEPSS 1%

    openmage · magentoJan 27, 2023

  • Widget instances allows a hacker to inject an executable file on the server on OpenMage

    HighCVSS 7.2No exploitEPSS 3%

    openmage · openmageJan 21, 2021

  • Layout XML RCE Vulnerability in OpenMage

    HighCVSS 7.2No exploitEPSS 2%

    openmage · openmageJan 20, 2021

  • Layout XML Arbitrary Code Fix

    HighCVSS 7.2No exploitEPSS 2%

    openmage · openmageAug 27, 2021

  • CMS Editor code execution

    HighCVSS 7.2No exploitEPSS 2%

    openmage · openmageJan 21, 2021

  • Data Flow Sanitation Issue Fix

    HighCVSS 7.2No exploitEPSS 1%

    openmage · magentoAug 27, 2021

  • OpenMage LTS arbitrary command execution in custom layout update through blocks

    HighCVSS 7.2No exploitEPSS 1%

    openmage · magentoJan 27, 2023

  • OpenMage LTS arbitrary file deletion in customer media allows for remote code execution

    HighCVSS 7.2No exploitEPSS 1%

    openmage · magentoJan 27, 2023

  • In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can b

    HighCVSS 7.2No exploitEPSS 1%

    openmage · magentoOct 21, 2020

  • OpenMage LTS DataFlow upload remote code execution vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    openmage · magentoJan 27, 2023

  • Backport for CVE-2021-21024 Blind SQLi from Magento 2

    HighCVSS 7.2No exploitEPSS 1%

    openmage · magentoApr 21, 2021

  • Magento's X-Original-Url header can expose admin url

    MediumCVSS 5.3No exploitEPSS 0%

    openmage · magentoFeb 4, 2026

  • OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant

    MediumCVSS 5.3No exploitEPSS 0%

    openmage · magentoApr 20, 2026

  • OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module

    MediumCVSS 4.9No exploitEPSS 1%

    openmage · magentoApr 20, 2026

  • Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs

    MediumCVSS 4.8No exploitEPSS 0%

    openmage · magentoJul 29, 2024

  • OpenMage is vulnerable to XSS in Admin Notifications

    MediumCVSS 4.6No exploitEPSS 0%

    openmage · magentoNov 6, 2025

  • Magneto-lts vulnerable to Cross-Site Request Forgery

    MediumCVSS 4.3No exploitEPSS 0%

    openmage · magentoJan 27, 2023