OpenMage records
23 published records for vendor openmage.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 87%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
- CWE-502 Deserialization of Untrusted Data2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-21426No exploit | Fixes a bug in Zend Framework's Stream HTTP Wrapperopenmage · magento · CWE-502 | Critical9.8 | — | 1.2% | Apr 21, 2021 |
35Monitor | CVE-2021-41144No exploit | OpenMage LTS authenticated remote code execution through layout updateopenmage · magento · CWE-77 | High8.8 | — | 1.2% | Jan 27, 2023 |
34Monitor | CVE-2026-40488No exploit | OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Executionopenmage · magento · CWE-434 | High8.7 | — | 1.0% | Apr 20, 2026 |
32Monitor | CVE-2020-15151No exploit | Observable Timing Discrepancy in OpenMage LTSopenmage · openmage long term support · CWE-203 | High8.0 | — | 0.9% | Aug 19, 2020 |
32Monitor | CVE-2026-25524Proof of concept | OpenMage LTS's Phar Deserialization leads to Remote Code Executionopenmage · magento · CWE-502 | High8.1 | — | 0.7% | Apr 20, 2026 |
30Monitor | CVE-2023-41879No exploit | Magento LTS's guest order "protect code" can be brute-forced too easilyopenmage · magento · CWE-330 | High7.5 | — | 1.3% | Sep 11, 2023 |
30Monitor | CVE-2023-23617No exploit | OpenMage LTS has DoS vulnerability in MaliciousCode filteropenmage · magento · CWE-835 | High7.5 | — | 1.0% | Jan 27, 2023 |
29Monitor | CVE-2020-26285No exploit | Widget instances allows a hacker to inject an executable file on the server on OpenMageopenmage · openmage · CWE-22 | High7.2 | — | 2.9% | Jan 21, 2021 |
29Monitor | CVE-2020-26252No exploit | Layout XML RCE Vulnerability in OpenMageopenmage · openmage · CWE-22 | High7.2 | — | 2.1% | Jan 20, 2021 |
29Monitor | CVE-2021-32758No exploit | Layout XML Arbitrary Code Fixopenmage · openmage · CWE-91 | High7.2 | — | 2.0% | Aug 27, 2021 |
29Monitor | CVE-2020-26295No exploit | CMS Editor code executionopenmage · openmage · CWE-22 | High7.2 | — | 1.8% | Jan 21, 2021 |
28Monitor | CVE-2021-32759No exploit | Data Flow Sanitation Issue Fixopenmage · magento · CWE-20 | High7.2 | — | 1.3% | Aug 27, 2021 |
28Monitor | CVE-2021-39217No exploit | OpenMage LTS arbitrary command execution in custom layout update through blocksopenmage · magento · CWE-77 | High7.2 | — | 1.3% | Jan 27, 2023 |
28Monitor | CVE-2021-41143No exploit | OpenMage LTS arbitrary file deletion in customer media allows for remote code executionopenmage · magento · CWE-77 | High7.2 | — | 1.3% | Jan 27, 2023 |
28Monitor | CVE-2020-15244No exploit | In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can bopenmage · magento · CWE-74 | High7.2 | — | 1.3% | Oct 21, 2020 |
28Monitor | CVE-2021-41231No exploit | OpenMage LTS DataFlow upload remote code execution vulnerabilityopenmage · magento · CWE-77 | High7.2 | — | 1.2% | Jan 27, 2023 |
28Monitor | CVE-2021-21427No exploit | Backport for CVE-2021-21024 Blind SQLi from Magento 2openmage · magento · CWE-89 | High7.2 | — | 1.1% | Apr 21, 2021 |
21Monitor | CVE-2026-25523No exploit | Magento's X-Original-Url header can expose admin urlopenmage · magento · CWE-200 | Medium5.3 | — | 0.4% | Feb 4, 2026 |
21Monitor | CVE-2026-40098No exploit | OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variantopenmage · magento · CWE-862 | Medium5.3 | — | 0.2% | Apr 20, 2026 |
19Monitor | CVE-2026-25525No exploit | OpenMage LTS has Path Traversal Filter Bypass in Dataflow Moduleopenmage · magento · CWE-22 | Medium4.9 | — | 0.7% | Apr 20, 2026 |
19Monitor | CVE-2024-41676No exploit | Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configsopenmage · magento · CWE-79 | Medium4.8 | — | 0.4% | Jul 29, 2024 |
18Monitor | CVE-2025-64174No exploit | OpenMage is vulnerable to XSS in Admin Notificationsopenmage · magento · CWE-79 | Medium4.6 | — | 0.2% | Nov 6, 2025 |
17Monitor | CVE-2021-21395No exploit | Magneto-lts vulnerable to Cross-Site Request Forgeryopenmage · magento · CWE-352 | Medium4.3 | — | 0.4% | Jan 27, 2023 |
- CVE-2021-2142639Monitor
Fixes a bug in Zend Framework's Stream HTTP Wrapper
CriticalCVSS 9.8No exploitEPSS 1%openmage · magentoApr 21, 2021
- CVE-2021-4114435Monitor
OpenMage LTS authenticated remote code execution through layout update
HighCVSS 8.8No exploitEPSS 1%openmage · magentoJan 27, 2023
- CVE-2026-4048834Monitor
OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution
HighCVSS 8.7No exploitEPSS 1%openmage · magentoApr 20, 2026
- CVE-2020-1515132Monitor
Observable Timing Discrepancy in OpenMage LTS
HighCVSS 8.0No exploitEPSS 1%openmage · openmage long term supportAug 19, 2020
- CVE-2026-2552432Monitor
OpenMage LTS's Phar Deserialization leads to Remote Code Execution
HighCVSS 8.1Proof of conceptEPSS 1%openmage · magentoApr 20, 2026
- CVE-2023-4187930Monitor
Magento LTS's guest order "protect code" can be brute-forced too easily
HighCVSS 7.5No exploitEPSS 1%openmage · magentoSep 11, 2023
- CVE-2023-2361730Monitor
OpenMage LTS has DoS vulnerability in MaliciousCode filter
HighCVSS 7.5No exploitEPSS 1%openmage · magentoJan 27, 2023
- CVE-2020-2628529Monitor
Widget instances allows a hacker to inject an executable file on the server on OpenMage
HighCVSS 7.2No exploitEPSS 3%openmage · openmageJan 21, 2021
- CVE-2020-2625229Monitor
Layout XML RCE Vulnerability in OpenMage
HighCVSS 7.2No exploitEPSS 2%openmage · openmageJan 20, 2021
- CVE-2021-3275829Monitor
Layout XML Arbitrary Code Fix
HighCVSS 7.2No exploitEPSS 2%openmage · openmageAug 27, 2021
- CVE-2020-2629529Monitor
CMS Editor code execution
HighCVSS 7.2No exploitEPSS 2%openmage · openmageJan 21, 2021
- CVE-2021-3275928Monitor
Data Flow Sanitation Issue Fix
HighCVSS 7.2No exploitEPSS 1%openmage · magentoAug 27, 2021
- CVE-2021-3921728Monitor
OpenMage LTS arbitrary command execution in custom layout update through blocks
HighCVSS 7.2No exploitEPSS 1%openmage · magentoJan 27, 2023
- CVE-2021-4114328Monitor
OpenMage LTS arbitrary file deletion in customer media allows for remote code execution
HighCVSS 7.2No exploitEPSS 1%openmage · magentoJan 27, 2023
- CVE-2020-1524428Monitor
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can b
HighCVSS 7.2No exploitEPSS 1%openmage · magentoOct 21, 2020
- CVE-2021-4123128Monitor
OpenMage LTS DataFlow upload remote code execution vulnerability
HighCVSS 7.2No exploitEPSS 1%openmage · magentoJan 27, 2023
- CVE-2021-2142728Monitor
Backport for CVE-2021-21024 Blind SQLi from Magento 2
HighCVSS 7.2No exploitEPSS 1%openmage · magentoApr 21, 2021
- CVE-2026-2552321Monitor
Magento's X-Original-Url header can expose admin url
MediumCVSS 5.3No exploitEPSS 0%openmage · magentoFeb 4, 2026
- CVE-2026-4009821Monitor
OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant
MediumCVSS 5.3No exploitEPSS 0%openmage · magentoApr 20, 2026
- CVE-2026-2552519Monitor
OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module
MediumCVSS 4.9No exploitEPSS 1%openmage · magentoApr 20, 2026
- CVE-2024-4167619Monitor
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
MediumCVSS 4.8No exploitEPSS 0%openmage · magentoJul 29, 2024
- CVE-2025-6417418Monitor
OpenMage is vulnerable to XSS in Admin Notifications
MediumCVSS 4.6No exploitEPSS 0%openmage · magentoNov 6, 2025
- CVE-2021-2139517Monitor
Magneto-lts vulnerable to Cross-Site Request Forgery
MediumCVSS 4.3No exploitEPSS 0%openmage · magentoJan 27, 2023