openmage/magento-lts
Official OpenMage LTS codebase | Migrate easily from Magento Community Edition in minutes! Download the source code for free or contribute to OpenMage LTS | Security vulnerability patches, bug fixes, performance improvements and more.
Activity
- Latest release
- 4mo ago
- Total releases
- 94
- Cadence
- ~18 days
- Last 12 months
- 3
Reach
- Stars
- 928
Details
- License
- unknown
- First release
- May 04, 2015
| Version | Released | |
|---|---|---|
v20.18.0
minor
|
v20.18.0
minor
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
v20.17.0
minor
3 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev |
v20.17.0
minor
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v20.16.0
minor
8 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev |
v20.16.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
v20.15.0
minor
9 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev |
v20.15.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
v20.14.0
minor
9 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev | ||
v20.13.0
minor
9 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev |
v20.13.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
v20.12.3
patch
9 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev |
v20.12.3
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
v20.12.2
patch
10 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev | ||
v20.12.1
patch
10 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev | ||
v20.12.0
minor
10 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev | ||
v20.11.0
minor
10 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev |
v20.11.0
minor
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
v20.10.2
patch
10 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev |
v20.10.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v20.10.1
patch
10 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev | ||
v21.0.0-beta2
pre
|
v21.0.0-beta2
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v20.10.0
minor
11 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v20.9.0
minor
11 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v20.9.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
v20.8.0
minor
11 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v20.7.0
minor
11 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v21.0.0-beta1
pre
|
v21.0.0-beta1
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
v20.6.0
minor
11 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v19.5.3
patch
12 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev |
v19.5.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v20.5.0
minor
11 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v20.4.0
minor
12 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev |
v20.4.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v20.3.0
minor
12 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev |
v20.3.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v19.5.2
patch
13 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev | ||
v20.2.0
minor
12 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
v20.1.1
patch
13 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev |
v20.1.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v19.5.1
patch
13 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev | ||
v20.1.0
minor
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
v20.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v19.5.0
minor
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
v19.5.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v20.1.0-rc7
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v20.1.0-rc6
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v20.1.0-rc5
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v19.5.0-rc5
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v20.1.0-rc4
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v19.5.0-rc4
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v20.1.0-rc3
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v19.5.0-rc3
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v20.1.0-rc2
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
v20.1.0-rc2
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v19.5.0-rc2
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
v19.5.0-rc2
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v20.1.0-rc1
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
v20.1.0-rc1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v19.5.0-rc1
pre
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
v19.5.0-rc1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v20.0.20
patch
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v19.4.23
patch
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v19.4.22
patch
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v20.0.19
patch
14 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
v19.4.21
patch
20 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-41231
GHSA-h632-p764-pjqm
Jan 27, 2023
DataFlow upload remote code execution vulnerability
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactAn administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-41144
GHSA-5j2g-3ph4-rgvm
Jan 27, 2023
Fix for authenticated remote code execution through layout update
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactA layout block was able to bypass the block blacklist to execute remote code. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-23617
GHSA-3p73-mm7v-4f6m
Jan 27, 2023
DoS vulnerability in MaliciousCode filter
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
ImpactInfinite loop in malicious code filter in certain conditions. WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41143
GHSA-5vpv-xmcj-9q85
Jan 27, 2023
Fix for arbitrary file deletion in customer media allows for remote code execution
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactMagento admin users with access to the customer media could execute code on the server. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39217
GHSA-c9q3-r4rv-mjm7
Jan 27, 2023
Fix for arbitrary command execution in custom layout update through blocks
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactCustom Layout enabled admin users to execute arbitrary commands via block methods. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21395
GHSA-r3c9-9j5q-pwv4
Jan 26, 2023
magento-lts Reset Password not protected against well-timed CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
ImpactPassword reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password. PatchesPR forthcoming WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v19.4.20
patch
20 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-41231
GHSA-h632-p764-pjqm
Jan 27, 2023
DataFlow upload remote code execution vulnerability
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactAn administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-41144
GHSA-5j2g-3ph4-rgvm
Jan 27, 2023
Fix for authenticated remote code execution through layout update
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactA layout block was able to bypass the block blacklist to execute remote code. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-23617
GHSA-3p73-mm7v-4f6m
Jan 27, 2023
DoS vulnerability in MaliciousCode filter
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
ImpactInfinite loop in malicious code filter in certain conditions. WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41143
GHSA-5vpv-xmcj-9q85
Jan 27, 2023
Fix for arbitrary file deletion in customer media allows for remote code execution
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactMagento admin users with access to the customer media could execute code on the server. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39217
GHSA-c9q3-r4rv-mjm7
Jan 27, 2023
Fix for arbitrary command execution in custom layout update through blocks
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactCustom Layout enabled admin users to execute arbitrary commands via block methods. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21395
GHSA-r3c9-9j5q-pwv4
Jan 26, 2023
magento-lts Reset Password not protected against well-timed CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
ImpactPassword reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password. PatchesPR forthcoming WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v20.0.18
patch
20 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-41231
GHSA-h632-p764-pjqm
Jan 27, 2023
DataFlow upload remote code execution vulnerability
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactAn administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-41144
GHSA-5j2g-3ph4-rgvm
Jan 27, 2023
Fix for authenticated remote code execution through layout update
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactA layout block was able to bypass the block blacklist to execute remote code. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-23617
GHSA-3p73-mm7v-4f6m
Jan 27, 2023
DoS vulnerability in MaliciousCode filter
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
ImpactInfinite loop in malicious code filter in certain conditions. WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41143
GHSA-5vpv-xmcj-9q85
Jan 27, 2023
Fix for arbitrary file deletion in customer media allows for remote code execution
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactMagento admin users with access to the customer media could execute code on the server. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39217
GHSA-c9q3-r4rv-mjm7
Jan 27, 2023
Fix for arbitrary command execution in custom layout update through blocks
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactCustom Layout enabled admin users to execute arbitrary commands via block methods. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21395
GHSA-r3c9-9j5q-pwv4
Jan 26, 2023
magento-lts Reset Password not protected against well-timed CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
ImpactPassword reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password. PatchesPR forthcoming WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v19.4.19
patch
20 CVEs
CVE-2026-42458
GHSA-x8jv-q8j2-487c
May 06, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Medium
Network
Low
None
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles. Steps to produce
File Link: customer_20260212_204335.csv
ImpactCookie stealing, JS deface, many more Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42207
GHSA-qpgq-5g92-j5q8
May 05, 2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Summary
Vulnerable path:
Secure peer (priceAction()):
Steps to ReproducePrerequisites
Step 1 – Authenticate as a Customer (Attacker controls the crafted link; victim must be logged in)The Step 2 – Craft the Malicious URLThe
Key conditions:
ImpactTechnical ImpactAn attacker who controls the Business-Level Attack Vectors| Scenario | Description | |------------------------|-----------------------------------------------------------------------------| | Credential phishing | Craft a link claiming to show a stock notification. Customer lands on attacker’s login clone and reuses their password. | | OAuth / SSO token theft| If the store uses a social login or “Login with Google” flow, the attacker can inject their redirect_uri via the open redirect, stealing OAuth tokens. | | Affiliate fraud | Redirect customers from the legitimate store to a competing retailer after they click a “notify me” link. | | Malware distribution | Redirect to drive-by-download pages with the store’s reputation acting as social proof. | PropagationA single malicious link can be embedded in:
Recommended FixApply the same This is an AI-generated report. An attempt was made to test the same PoC against the online demo https://demo.openmage.org/ but it couldn't be reproduced. It was only reproduced against the local setup env against the latest version. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-42155
GHSA-2cwr-gcf9-pvxr
May 05, 2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Critical
Network
Low
None
None
Affected Version: OpenMage LTS ≤ 20.16.0 (confirmed on Affected File: SummaryThe XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG):
All inputs to the MD5 hash are time-derived and non-secure: | Input | Value | Predictability |
|----------------------------|---------------------------------------------------|----------------------------------------|
| Because the resulting digest relies entirely on the timestamp and the PHP internal LCG state, the effective entropy is severely constrained. This violates the OWASP ASVS v4 requirement of ≥ 64 bits of entropy (V3.2.2) and NIST SP 800-63B standards. By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack active API sessions. Technical AnalysisCode Path
Note: Live EvidenceFive consecutive XML-RPC login tokens were collected from a live OpenMage 20.16.0 container, all generated within a single Unix second (
The µsecond portion is directly observable by measuring request-to-response latency. The only variance preventing immediate prediction is the LCG float component, which is seeded deterministically. Steps to Reproduce (Online Brute-Force Scenario)Because validation requires live HTTP requests, this exploit relies on narrowing the entropy window and abusing the lack of API rate limits. Step 1 – Record Login TimestampAn attacker observes the precise moment a victim authenticates to Step 2 – Generate Candidate PoolThe attacker reconstructs the MD5 format using the known timestamp, the estimated microsecond window, and bounds the LCG float based on known server PID ranges (or via a
Step 3 – API Brute-Force (Session Hijack)Because the
A non-fault response (HTTP 200 containing data) confirms the session is successfully hijacked. ImpactTechnical ImpactSuccessful session prediction grants the attacker all capabilities of the authenticated API user. The XML-RPC API exposes endpoints for:
Business Impact
Affected API ProtocolsThe same vulnerable
Recommended FixReplace the time-derived token with a cryptographically secure random value:
I have also tried to test it against the demo site demo.openmage.org, but appeared the SOAP API endpoints are disabled on the demo environment I have also included the full poc I used instead of being attached because Gmail will eventually block it otherwise (shrunk):
This is an AI-generated report validated by a human. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 79 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.17.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.18.0
References Updated May 16, 2026 · Source: OSV.dev
CVE-2026-40488
GHSA-3j5q-7q7h-2hhv
Apr 21, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
Network
Low
Low
None
The product custom option file upload in OpenMage LTS uses an incomplete blocklist ( Affected Version
Root CauseThe file upload handler uses
This misses the comprehensive
Vulnerable Code
Steps to Reproduce1. Environment SetupTarget: OpenMage LTS with Apache+mod_php or Apache+PHP-FPM (with .phtml handler) 2. Exploitation
Result: 3. Code ExecutionOpenMage derives the uploaded file's storage path deterministically from two values the attacker already controls: Subdirectory —
Filename —
Because the attacker writes the webshell themselves, both the filename prefix and file contents are known before the upload request is sent. The full URL can be pre-computed:
Result: RCE Confirmed Affected Deployments| Configuration | Status |
|---------------|--------|
| Apache + mod_php (with Impact
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40098
GHSA-665x-ppc4-685w
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Medium
Network
Low
Low
None
Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variantSummaryThe shared wishlist add-to-cart endpoint authorizes access with a public This lets an attacker use:
to import victim item B into the attacker's cart through the shared wishlist flow for wishlist A. Because the victim item's stored Vulnerability Type
Root CauseIn
Relevant lines:
There is no check that:
The safe owner flow in The imported item keeps its original
Security ImpactBaseline impactAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code. This is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text. Stronger variant: cross-user file disclosureIf the victim item contains a custom option of type
The file option renderer in
The downloader in
It does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported. Steps To ReproduceLab data
ReproductionSend:
Where:
Expected resultThe request should be rejected because the item does not belong to the shared wishlist referenced by the Actual resultThe application imports victim item Verified EvidenceBaseline variantPreviously verified at quote/option level in lab:
This shows that the attacker's cart received victim-private custom-option data from another user's wishlist item. File-disclosure variantPreviously verified in lab after importing a victim file-option payload:
This URL was generated from imported quote item option data containing the victim file metadata and secret key. Why This Is A Valid BugThis is not a timing issue and does not depend on non-default security settings. The bug is a direct authorization failure:
That is a broken object-level authorization issue with clear cross-user impact. RemediationIn
Defense in depth:
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-25525
GHSA-6vqf-6fhm-7rc6
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
The Dataflow module in OpenMage LTS uses a weak blacklist filter ( | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------- | | Attack Vector (AV) | Network | Exploitable via admin panel | | Attack Complexity (AC) | Low | Simple bypass pattern | | Privileges Required (PR) | High | Requires admin authentication | | User Interaction (UI) | None | No additional user interaction needed | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Can read sensitive system files | | Integrity (I) | None | Read-only vulnerability | | Availability (A) | None | No impact on availability | Affected Products
Affected Files| File | Line | Vulnerable Code |
| ------------------------------------------------------------ | ---- | ---------------------------------------- |
| Vulnerability DetailsThe Dataflow module allows administrators to import data from files. The
However, Bypass Examples| Input | After Attack Scenario
Proof of Concept
RemediationReplace the weak
Using WorkaroundsIf immediate upgrade is not possible:
ImpactAn attacker with admin access can read sensitive files including:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References
Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25524
GHSA-fg79-cr9c-7369
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP functions such as | Metric | Value | Justification | | ------------------------ | --------- | ------------------------------------------------ | | Attack Vector (AV) | Network | Exploitable via file upload and web requests | | Attack Complexity (AC) | High | Requires file upload + triggering phar:// access | | Privileges Required (PR) | None | Some upload vectors don't require authentication | | User Interaction (UI) | None | Exploitation is automatic once triggered | | Scope (S) | Unchanged | Impacts the vulnerable component | | Confidentiality (C) | High | Full system access via RCE | | Integrity (I) | High | Arbitrary code execution | | Availability (A) | High | Complete system compromise possible | Affected Products
Affected Files| File | Line | Vulnerable Function |
| --------------------------------------------------------- | ---- | ---------------------------------------------- |
| Vulnerability DetailsPHP's phar (PHP Archive) format stores metadata that is serialized. When PHP's stream wrapper functions access a file using the A polyglot file can be crafted that is both a valid image (passing initial validation) and a valid phar archive containing malicious serialized objects. When the application later processes this file using Attack Flow
Proof of Concept
RemediationBlock
Additionally, ICO files (which cannot be re-encoded by GD) are now scanned for phar signatures:
Additional hardening measures:
Note: Existing uploaded ICO files will continue to work. Only new ICO uploads will be rejected. Users are encouraged to use PNG favicons for new uploads. WorkaroundsIf immediate upgrade is not possible:
CreditThis vulnerability was discovered and responsibly disclosed by blackhat2013 through HackerOne. Timeline
Source: https://hackerone.com/reports/3482926 Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.17.0
References Updated Apr 21, 2026 · Source: OSV.dev
CVE-2026-25523
GHSA-jg68-vhv3-9r8f
Feb 02, 2026
Magento's X-Original-Url header can expose admin url
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
ImpactThe admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. PatchesThe bug comes from the Zend library and is patche by unsetting the header in the bootstrap process. WorkaroundsUnset the ReferencesThe activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..) CreditAnees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 78 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.16.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.1
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-64174
GHSA-qv78-c8hc-438r
Nov 03, 2025
OpenMage vulnerable to XSS in Admin Notifications
Medium
Network
Low
High
SummaryOpenMage versions v20.15.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. DetailsUnescaped translation strings and URLs are printed into contexts inside
PoC
ImpactThe vulnerability is only exploitable by an attacker with administrative or translation privileges. Malicious JavaScript may be executed in a victim’s browser when they browse to the admin page containing the vulnerable fields. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 77 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.12.3
v20.13.0
v20.14.0
v20.15.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.16.0
References Updated Nov 06, 2025 · Source: OSV.dev
CVE-2025-27400
GHSA-5pxh-89cx-4668
Mar 03, 2025
Magento LTS vulnerable to stored XSS in theme config fields
2.9
/ 10
Low
Adjacent
High
High
Required
Unchanged
None
Low
Low
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag. ImpactA malicious user with access to this configuration field could use a Stored XSS to affect other authenticated admin users in the admin panel. The attack requires an admin user with configuration access, so in practice, it is not very likely to be used for gaining elevated privileges, although it could theoretically be used to impersonate other users. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 73 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.10.1
v20.10.2
v20.11.0
v20.12.0
v20.12.1
v20.12.2
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.12.3
References
Updated Mar 03, 2025 · Source: OSV.dev
CVE-2024-41676
GHSA-5vrp-638w-p8m2
Jul 29, 2024
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Medium
Network
Low
High
None
ImpactThis XSS vulnerability is about the system configs
They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. While this is in most usage scenarios not a relevant issue, some people work with more restrictive roles in the backend. Here the ability to inject JavaScript with these settings would be an unintended and unwanted privilege. PatchesHas the problem been patched? What versions should users upgrade to? The problem is patched with Version 20.10.1 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Possible mitigations are
For Users relying on this possibilitySome Users might actually rely on the ability to use html there.
You can restore the previous behavior by making use of the new introduced CreditCredit goes to Aakash Adhikari @justlife4x4 for finding this issue Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 67 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.10.0
v20.2.0
v20.3.0
v20.4.0
v20.5.0
v20.6.0
v20.7.0
v20.8.0
v20.9.0
Fixed in
20.10.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-gp6m-fq6h-cjcx
Feb 27, 2024
Magento LTS vulnerable to stored XSS in admin file form
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
SummaryOpenMage is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Details
PoC
ImpactAffects admins that have access to any fileupload field in admin in core or custom implementations. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Affected versions
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
+ 60 more Show less
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
v20.2.0
v20.3.0
v20.4.0
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
Fixed in
19.5.3
20.5.0
References Updated Nov 30, 2024 · Source: OSV.dev
GHSA-9j5w-2cqc-cwj9
Dec 08, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
7.5
/ 10
High
Network
Low
High
Required
Changed
High
Low
Low
From HackerOne report #1948040 by Halit AKAYDIN (hltakydn) ImpactWhat kind of vulnerability is it? Who is impacted? The TinyMCE WYSIWYG editor fails to filter scripts when rendering the HTML in specially crafted HTML tags. PatchesHas the problem been patched? What versions should users upgrade to? This vulnerability was fixed in version 20.2.0 by upgrading TinyMCE to a recent version in https://github.com/OpenMage/magento-lts/pull/3220 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? The WYSIWYG editor features could be disabled in the configuration. Possibly some WAF appliances would filter this attack. ReferencesAre there any links users can visit to find out more? The attack is simply an exploit of the "onmouseover" attribute of an Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 58 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v19.5.1
v19.5.2
v19.5.3
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
v20.1.1
Fixed in
20.2.0
References Updated Dec 04, 2024 · Source: OSV.dev
CVE-2023-41879
GHSA-9358-cpvx-c2qp
Sep 11, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactGuest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. PatchesNone. WorkaroundsImplementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route ( ReferencesEmail from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org: SummaryThe German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test: The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily easily guessed transaction numbers or names. Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers. DetailsCustomers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information. Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The random value consists of six characters, where these are taken from the alphabet [0-9a-f]. In the best case, i.e. when using a cryptographically secure random number generator, this corresponds to an entropy of 24 bits. Furthermore, the order numbers are assigned incrementally, so that the number range can be narrowed down or an upper limit determined by placing an order. Specifically, this results in the risk that an attacking entity can iterate over all possible values of the cookie's random value. If successful, the billing address, shipping address, payment details and the ordered items can be viewed. The attack only works for orders made as a guest. PoCThe request/response pair shows the retrieval of an order. It should be noted in particular, that the cookie is not bound to a session. The response has been formatted for formatted for readability. Request:
Response:
ImpactInformation disclosure. Read as well as write access to sensitive information of persons or accounts and the execution of actions on their behalf must always be secured by strong authentication. This can be ensured, for example, by enforcing strong passwords or MFA. For temporary accesses to sensitive information, temporary passwords or authentication tokens or comparable data that an attacking entity cannot easily guess or determine should be used. Random values should have sufficient entropy so that searching the number space is impractical for attacking entities. Furthermore, such queries should be limited by rate limiting. The exact attack effort cannot be determined, since this requires the proportion of the proportion of orders that were placed without an account and since the performance of the performance of the production system is likely to differ from that of the test system. In a test run, 1000 requests could be made within 36 seconds. Part of the execution is shown in the screenshot. The complete search of the number space for the random value would take 6 days 23 hours 46 minutes. Accordingly, the expected value is about 3.5 days. If every third order is executed without an account, the effort must be multiplied by a factor of 3. Mit freundlichen Grüßen Frank Rochlitzer (github: theroch) Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 54 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.22
v19.4.23
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v19.5.0
v19.5.0-rc1
v19.5.0-rc2
v19.5.0-rc3
v19.5.0-rc4
v19.5.0-rc5
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.19
v20.0.2
v20.0.20
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.1.0
v20.1.0-rc1
v20.1.0-rc2
v20.1.0-rc3
v20.1.0-rc4
v20.1.0-rc5
v20.1.0-rc6
v20.1.0-rc7
Fixed in
19.5.1
20.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-41231
GHSA-h632-p764-pjqm
Jan 27, 2023
DataFlow upload remote code execution vulnerability
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactAn administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-41144
GHSA-5j2g-3ph4-rgvm
Jan 27, 2023
Fix for authenticated remote code execution through layout update
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactA layout block was able to bypass the block blacklist to execute remote code. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-23617
GHSA-3p73-mm7v-4f6m
Jan 27, 2023
DoS vulnerability in MaliciousCode filter
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
ImpactInfinite loop in malicious code filter in certain conditions. WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41143
GHSA-5vpv-xmcj-9q85
Jan 27, 2023
Fix for arbitrary file deletion in customer media allows for remote code execution
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactMagento admin users with access to the customer media could execute code on the server. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39217
GHSA-c9q3-r4rv-mjm7
Jan 27, 2023
Fix for arbitrary command execution in custom layout update through blocks
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
ImpactCustom Layout enabled admin users to execute arbitrary commands via block methods. Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21395
GHSA-r3c9-9j5q-pwv4
Jan 26, 2023
magento-lts Reset Password not protected against well-timed CSRF
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
ImpactPassword reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password. PatchesPR forthcoming WorkaroundsNone Affected versions
1.9.1.1
1.9.2.0
1.9.2.1
1.9.2.2
1.9.2.3
1.9.2.4
1.9.3.0
1.9.3.1
v19.4.0
v19.4.1
v19.4.10
v19.4.11
+ 36 more Show less
v19.4.12
v19.4.13
v19.4.14
v19.4.15
v19.4.16
v19.4.17
v19.4.18
v19.4.19
v19.4.2
v19.4.20
v19.4.21
v19.4.3
v19.4.4
v19.4.5
v19.4.6
v19.4.7
v19.4.8
v19.4.9
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.12
v20.0.13
v20.0.14
v20.0.15
v20.0.16
v20.0.17
v20.0.18
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
Fixed in
19.4.22
20.0.19
References
Updated Jul 08, 2026 · Source: OSV.dev |