Записи OpenMage
23 опубликованных записей вендора openmage.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 87 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
- CWE-502 Deserialization of Untrusted Data2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-21426Эксплойта нет | Fixes a bug in Zend Framework's Stream HTTP Wrapperopenmage · magento · CWE-502 | Критическая9,8 | — | 1,2 % | 21 апр. 2021 г. |
35Наблюдать | CVE-2021-41144Эксплойта нет | OpenMage LTS authenticated remote code execution through layout updateopenmage · magento · CWE-77 | Высокая8,8 | — | 1,2 % | 27 янв. 2023 г. |
34Наблюдать | CVE-2026-40488Эксплойта нет | OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Executionopenmage · magento · CWE-434 | Высокая8,7 | — | 1,0 % | 20 апр. 2026 г. |
32Наблюдать | CVE-2020-15151Эксплойта нет | Observable Timing Discrepancy in OpenMage LTSopenmage · openmage long term support · CWE-203 | Высокая8,0 | — | 0,9 % | 19 авг. 2020 г. |
32Наблюдать | CVE-2026-25524Proof of concept | OpenMage LTS's Phar Deserialization leads to Remote Code Executionopenmage · magento · CWE-502 | Высокая8,1 | — | 0,7 % | 20 апр. 2026 г. |
30Наблюдать | CVE-2023-41879Эксплойта нет | Magento LTS's guest order "protect code" can be brute-forced too easilyopenmage · magento · CWE-330 | Высокая7,5 | — | 1,3 % | 11 сент. 2023 г. |
30Наблюдать | CVE-2023-23617Эксплойта нет | OpenMage LTS has DoS vulnerability in MaliciousCode filteropenmage · magento · CWE-835 | Высокая7,5 | — | 1,0 % | 27 янв. 2023 г. |
29Наблюдать | CVE-2020-26285Эксплойта нет | Widget instances allows a hacker to inject an executable file on the server on OpenMageopenmage · openmage · CWE-22 | Высокая7,2 | — | 2,9 % | 21 янв. 2021 г. |
29Наблюдать | CVE-2020-26252Эксплойта нет | Layout XML RCE Vulnerability in OpenMageopenmage · openmage · CWE-22 | Высокая7,2 | — | 2,1 % | 20 янв. 2021 г. |
29Наблюдать | CVE-2021-32758Эксплойта нет | Layout XML Arbitrary Code Fixopenmage · openmage · CWE-91 | Высокая7,2 | — | 2,0 % | 27 авг. 2021 г. |
29Наблюдать | CVE-2020-26295Эксплойта нет | CMS Editor code executionopenmage · openmage · CWE-22 | Высокая7,2 | — | 1,8 % | 21 янв. 2021 г. |
28Наблюдать | CVE-2021-32759Эксплойта нет | Data Flow Sanitation Issue Fixopenmage · magento · CWE-20 | Высокая7,2 | — | 1,3 % | 27 авг. 2021 г. |
28Наблюдать | CVE-2021-39217Эксплойта нет | OpenMage LTS arbitrary command execution in custom layout update through blocksopenmage · magento · CWE-77 | Высокая7,2 | — | 1,3 % | 27 янв. 2023 г. |
28Наблюдать | CVE-2021-41143Эксплойта нет | OpenMage LTS arbitrary file deletion in customer media allows for remote code executionopenmage · magento · CWE-77 | Высокая7,2 | — | 1,3 % | 27 янв. 2023 г. |
28Наблюдать | CVE-2020-15244Эксплойта нет | In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can bopenmage · magento · CWE-74 | Высокая7,2 | — | 1,3 % | 21 окт. 2020 г. |
28Наблюдать | CVE-2021-41231Эксплойта нет | OpenMage LTS DataFlow upload remote code execution vulnerabilityopenmage · magento · CWE-77 | Высокая7,2 | — | 1,2 % | 27 янв. 2023 г. |
28Наблюдать | CVE-2021-21427Эксплойта нет | Backport for CVE-2021-21024 Blind SQLi from Magento 2openmage · magento · CWE-89 | Высокая7,2 | — | 1,1 % | 21 апр. 2021 г. |
21Наблюдать | CVE-2026-25523Эксплойта нет | Magento's X-Original-Url header can expose admin urlopenmage · magento · CWE-200 | Средняя5,3 | — | 0,4 % | 4 февр. 2026 г. |
21Наблюдать | CVE-2026-40098Эксплойта нет | OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variantopenmage · magento · CWE-862 | Средняя5,3 | — | 0,2 % | 20 апр. 2026 г. |
19Наблюдать | CVE-2026-25525Эксплойта нет | OpenMage LTS has Path Traversal Filter Bypass in Dataflow Moduleopenmage · magento · CWE-22 | Средняя4,9 | — | 0,7 % | 20 апр. 2026 г. |
19Наблюдать | CVE-2024-41676Эксплойта нет | Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configsopenmage · magento · CWE-79 | Средняя4,8 | — | 0,4 % | 29 июл. 2024 г. |
18Наблюдать | CVE-2025-64174Эксплойта нет | OpenMage is vulnerable to XSS in Admin Notificationsopenmage · magento · CWE-79 | Средняя4,6 | — | 0,2 % | 6 нояб. 2025 г. |
17Наблюдать | CVE-2021-21395Эксплойта нет | Magneto-lts vulnerable to Cross-Site Request Forgeryopenmage · magento · CWE-352 | Средняя4,3 | — | 0,4 % | 27 янв. 2023 г. |
- CVE-2021-2142639Наблюдать
Fixes a bug in Zend Framework's Stream HTTP Wrapper
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openmage · magento21 апр. 2021 г.
- CVE-2021-4114435Наблюдать
OpenMage LTS authenticated remote code execution through layout update
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %openmage · magento27 янв. 2023 г.
- CVE-2026-4048834Наблюдать
OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %openmage · magento20 апр. 2026 г.
- CVE-2020-1515132Наблюдать
Observable Timing Discrepancy in OpenMage LTS
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %openmage · openmage long term support19 авг. 2020 г.
- CVE-2026-2552432Наблюдать
OpenMage LTS's Phar Deserialization leads to Remote Code Execution
ВысокаяCVSS 8,1Proof of conceptEPSS 1 %openmage · magento20 апр. 2026 г.
- CVE-2023-4187930Наблюдать
Magento LTS's guest order "protect code" can be brute-forced too easily
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openmage · magento11 сент. 2023 г.
- CVE-2023-2361730Наблюдать
OpenMage LTS has DoS vulnerability in MaliciousCode filter
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openmage · magento27 янв. 2023 г.
- CVE-2020-2628529Наблюдать
Widget instances allows a hacker to inject an executable file on the server on OpenMage
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %openmage · openmage21 янв. 2021 г.
- CVE-2020-2625229Наблюдать
Layout XML RCE Vulnerability in OpenMage
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %openmage · openmage20 янв. 2021 г.
- CVE-2021-3275829Наблюдать
Layout XML Arbitrary Code Fix
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %openmage · openmage27 авг. 2021 г.
- CVE-2020-2629529Наблюдать
CMS Editor code execution
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %openmage · openmage21 янв. 2021 г.
- CVE-2021-3275928Наблюдать
Data Flow Sanitation Issue Fix
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %openmage · magento27 авг. 2021 г.
- CVE-2021-3921728Наблюдать
OpenMage LTS arbitrary command execution in custom layout update through blocks
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %openmage · magento27 янв. 2023 г.
- CVE-2021-4114328Наблюдать
OpenMage LTS arbitrary file deletion in customer media allows for remote code execution
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %openmage · magento27 янв. 2023 г.
- CVE-2020-1524428Наблюдать
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can b
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %openmage · magento21 окт. 2020 г.
- CVE-2021-4123128Наблюдать
OpenMage LTS DataFlow upload remote code execution vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %openmage · magento27 янв. 2023 г.
- CVE-2021-2142728Наблюдать
Backport for CVE-2021-21024 Blind SQLi from Magento 2
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %openmage · magento21 апр. 2021 г.
- CVE-2026-2552321Наблюдать
Magento's X-Original-Url header can expose admin url
СредняяCVSS 5,3Эксплойта нетEPSS 0 %openmage · magento4 февр. 2026 г.
- CVE-2026-4009821Наблюдать
OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant
СредняяCVSS 5,3Эксплойта нетEPSS 0 %openmage · magento20 апр. 2026 г.
- CVE-2026-2552519Наблюдать
OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module
СредняяCVSS 4,9Эксплойта нетEPSS 1 %openmage · magento20 апр. 2026 г.
- CVE-2024-4167619Наблюдать
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
СредняяCVSS 4,8Эксплойта нетEPSS 0 %openmage · magento29 июл. 2024 г.
- CVE-2025-6417418Наблюдать
OpenMage is vulnerable to XSS in Admin Notifications
СредняяCVSS 4,6Эксплойта нетEPSS 0 %openmage · magento6 нояб. 2025 г.
- CVE-2021-2139517Наблюдать
Magneto-lts vulnerable to Cross-Site Request Forgery
СредняяCVSS 4,3Эксплойта нетEPSS 0 %openmage · magento27 янв. 2023 г.