İçeriğe atla
Noroxi

OpenMage kayıtları

openmage üreticisine ait 23 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

23 kayıt
  • CVE-2021-21426
    39İzleyin

    Fixes a bug in Zend Framework's Stream HTTP Wrapper

    KritikCVSS 9,8İstismar yokEPSS %1

    openmage · magento21 Nis 2021

  • CVE-2021-41144
    35İzleyin

    OpenMage LTS authenticated remote code execution through layout update

    YüksekCVSS 8,8İstismar yokEPSS %1

    openmage · magento27 Oca 2023

  • CVE-2026-40488
    34İzleyin

    OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution

    YüksekCVSS 8,7İstismar yokEPSS %1

    openmage · magento20 Nis 2026

  • CVE-2020-15151
    32İzleyin

    Observable Timing Discrepancy in OpenMage LTS

    YüksekCVSS 8,0İstismar yokEPSS %1

    openmage · openmage long term support19 Ağu 2020

  • CVE-2026-25524
    32İzleyin

    OpenMage LTS's Phar Deserialization leads to Remote Code Execution

    YüksekCVSS 8,1Kavram kanıtıEPSS %1

    openmage · magento20 Nis 2026

  • CVE-2023-41879
    30İzleyin

    Magento LTS's guest order "protect code" can be brute-forced too easily

    YüksekCVSS 7,5İstismar yokEPSS %1

    openmage · magento11 Eyl 2023

  • CVE-2023-23617
    30İzleyin

    OpenMage LTS has DoS vulnerability in MaliciousCode filter

    YüksekCVSS 7,5İstismar yokEPSS %1

    openmage · magento27 Oca 2023

  • CVE-2020-26285
    29İzleyin

    Widget instances allows a hacker to inject an executable file on the server on OpenMage

    YüksekCVSS 7,2İstismar yokEPSS %3

    openmage · openmage21 Oca 2021

  • CVE-2020-26252
    29İzleyin

    Layout XML RCE Vulnerability in OpenMage

    YüksekCVSS 7,2İstismar yokEPSS %2

    openmage · openmage20 Oca 2021

  • CVE-2021-32758
    29İzleyin

    Layout XML Arbitrary Code Fix

    YüksekCVSS 7,2İstismar yokEPSS %2

    openmage · openmage27 Ağu 2021

  • CVE-2020-26295
    29İzleyin

    CMS Editor code execution

    YüksekCVSS 7,2İstismar yokEPSS %2

    openmage · openmage21 Oca 2021

  • CVE-2021-32759
    28İzleyin

    Data Flow Sanitation Issue Fix

    YüksekCVSS 7,2İstismar yokEPSS %1

    openmage · magento27 Ağu 2021

  • CVE-2021-39217
    28İzleyin

    OpenMage LTS arbitrary command execution in custom layout update through blocks

    YüksekCVSS 7,2İstismar yokEPSS %1

    openmage · magento27 Oca 2023

  • CVE-2021-41143
    28İzleyin

    OpenMage LTS arbitrary file deletion in customer media allows for remote code execution

    YüksekCVSS 7,2İstismar yokEPSS %1

    openmage · magento27 Oca 2023

  • CVE-2020-15244
    28İzleyin

    In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can b

    YüksekCVSS 7,2İstismar yokEPSS %1

    openmage · magento21 Eki 2020

  • CVE-2021-41231
    28İzleyin

    OpenMage LTS DataFlow upload remote code execution vulnerability

    YüksekCVSS 7,2İstismar yokEPSS %1

    openmage · magento27 Oca 2023

  • CVE-2021-21427
    28İzleyin

    Backport for CVE-2021-21024 Blind SQLi from Magento 2

    YüksekCVSS 7,2İstismar yokEPSS %1

    openmage · magento21 Nis 2021

  • CVE-2026-25523
    21İzleyin

    Magento's X-Original-Url header can expose admin url

    OrtaCVSS 5,3İstismar yokEPSS %0

    openmage · magento4 Şub 2026

  • CVE-2026-40098
    21İzleyin

    OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant

    OrtaCVSS 5,3İstismar yokEPSS %0

    openmage · magento20 Nis 2026

  • CVE-2026-25525
    19İzleyin

    OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module

    OrtaCVSS 4,9İstismar yokEPSS %1

    openmage · magento20 Nis 2026

  • CVE-2024-41676
    19İzleyin

    Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs

    OrtaCVSS 4,8İstismar yokEPSS %0

    openmage · magento29 Tem 2024

  • CVE-2025-64174
    18İzleyin

    OpenMage is vulnerable to XSS in Admin Notifications

    OrtaCVSS 4,6İstismar yokEPSS %0

    openmage · magento6 Kas 2025

  • CVE-2021-21395
    17İzleyin

    Magneto-lts vulnerable to Cross-Site Request Forgery

    OrtaCVSS 4,3İstismar yokEPSS %0

    openmage · magento27 Oca 2023