Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openmage

First CVE: Aug 20, 2020Active for: 6 yearsTotal CVEs: 23
45.5
VTI Score
High

Openmage maintains a focused vulnerability footprint centered on the Magento e-commerce platform and its long-term support variant, products that power a substantial installed base of online retail and marketplace deployments. The recurring exposure reflects the complexity of e-commerce application logic: path traversal and arbitrary file upload weaknesses recur across the platform, alongside command injection, unsafe deserialization, and cross-site request forgery issues that are characteristic of large PHP-based web applications handling user-supplied input and administrative functions. While the product count remains narrow, the platform's prevalence in production e-commerce environments means that individual vulnerabilities in this vendor's portfolio can affect a geographically distributed and economically significant set of merchants and their customers. Defenders should prioritize timely updates for deployed Magento instances and apply compensating controls for any versions where extended support has lapsed; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openmage over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2020
5 years ago
Most Recent CVE
Apr 20, 2026
95 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-40488HIGH
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwar
Apr 20, 20268.829NONO
CVE-2026-25524HIGH
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwar
Apr 20, 20268.129NONO
CVE-2021-41144HIGH
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20
Jan 27, 20238.828NONO
CVE-2021-21426CRITICAL
Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by
Apr 21, 20219.828NONO
CVE-2023-23617HIGH
OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19
Jan 28, 20237.524NONO
CVE-2021-41231HIGH
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to
Jan 27, 20237.224NONO
CVE-2021-41143HIGH
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4
Jan 27, 20237.224NONO
CVE-2021-39217HIGH
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 a
Jan 27, 20237.224NONO
CVE-2021-32759HIGH
OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for adm
Aug 27, 20217.224NONO
CVE-2021-32758HIGH
OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via
Aug 27, 20217.224NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
26%
70%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (91.3%)
High2 (8.7%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low3 (13.0%)
High13 (56.5%)
None7 (30.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openmage.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openmage — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openmage's Products

View all 1 CNAs →

Top CWEs