CVE Browser
Magento LTS: Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` - magento-lts
Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution
OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant
OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module
OpenMage LTS's Phar Deserialization leads to Remote Code Execution
Magento's X-Original-Url header can expose admin url
OpenMage is vulnerable to XSS in Admin Notifications
Magento vulnerable to stored XSS in theme config fields
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Magento LTS's guest order "protect code" can be brute-forced too easily
OpenMage LTS has DoS vulnerability in MaliciousCode filter
OpenMage LTS DataFlow upload remote code execution vulnerability
OpenMage LTS authenticated remote code execution through layout update
OpenMage LTS arbitrary file deletion in customer media allows for remote code execution
OpenMage LTS arbitrary command execution in custom layout update through blocks
Magneto-lts vulnerable to Cross-Site Request Forgery
Data Flow Sanitation Issue Fix
Layout XML Arbitrary Code Fix
Backport for CVE-2021-21024 Blind SQLi from Magento 2
Fixes a bug in Zend Framework's Stream HTTP Wrapper
CMS Editor code execution
Widget instances allows a hacker to inject an executable file on the server on OpenMage
Layout XML RCE Vulnerability in OpenMage
Showing 1 to 25 CVEs · page 1 (more available)