OpenMage Magento Lts(Magento)是OpenMage组织的一个电子商务系统。 OpenMage Magento Lts(Magento) 20.17.0之前版本存在安全漏洞,该漏洞源于处理phar://路径时可能触发反序列化,可能导致任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenMage | magento-lts | < 20.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-25525 | 4.9 MEDIUM | OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module |
| CVE-2026-40098 | OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private | |
| CVE-2026-40488 | OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code |
No comments yet