Openmage maintains a focused vulnerability footprint centered on the Magento e-commerce platform and its long-term support variant, products that power a substantial installed base of online retail and marketplace deployments. The recurring exposure reflects the complexity of e-commerce application logic: path traversal and arbitrary file upload weaknesses recur across the platform, alongside command injection, unsafe deserialization, and cross-site request forgery issues that are characteristic of large PHP-based web applications handling user-supplied input and administrative functions. While the product count remains narrow, the platform's prevalence in production e-commerce environments means that individual vulnerabilities in this vendor's portfolio can affect a geographically distributed and economically significant set of merchants and their customers. Defenders should prioritize timely updates for deployed Magento instances and apply compensating controls for any versions where extended support has lapsed; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openmage over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40488HIGH Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwar | Apr 20, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-25524HIGH Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwar | Apr 20, 2026 | 8.1 | 29 | NO | NO |
CVE-2021-41144HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20 | Jan 27, 2023 | 8.8 | 28 | NO | NO |
CVE-2021-21426CRITICAL Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by | Apr 21, 2021 | 9.8 | 28 | NO | NO |
CVE-2023-23617HIGH OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 | Jan 28, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-41231HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to | Jan 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-41143HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4 | Jan 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-39217HIGH OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 a | Jan 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-32759HIGH OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for adm | Aug 27, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-32758HIGH OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via | Aug 27, 2021 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openmage.
Media articles that mention a CVE ID that affects a product developed by Openmage — matched by CVE ID, not by vendor name.