Layout XML Arbitrary Code Fix
Modified: 7/8/2026
package
pkg:packagist/openmage/magento-lts
Layout XML Arbitrary Code Fix
Modified: 7/8/2026
Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Modified: 5/16/2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
Modified: 5/5/2026
DoS vulnerability in MaliciousCode filter
Modified: 9/10/2026
Fix for authenticated remote code execution through layout update
Modified: 7/8/2026
Magento LTS vulnerable to stored XSS in theme config fields
Modified: 3/3/2025
Fix for arbitrary file deletion in customer media allows for remote code execution
Modified: 7/8/2026
Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Modified: 9/10/2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Modified: 5/5/2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
Modified: 4/21/2026
Magento LTS's guest order "protect code" can be brute-forced too easily
Modified: 2/16/2024
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
Modified: 12/4/2024
Fix for arbitrary command execution in custom layout update through blocks
Modified: 7/8/2026
Observable Timing Discrepancy in OpenMage LTS
Modified: 7/8/2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
Modified: 4/21/2026
Backport for CVE-2021-21024 Blind SQLi from Magento 2
Modified: 7/8/2026
Magento LTS vulnerable to stored XSS in admin file form
Modified: 11/30/2024
DataFlow upload remote code execution vulnerability
Modified: 7/8/2026
Magento's X-Original-Url header can expose admin url
Modified: 2/10/2026
RCE via PHP Object injection via SOAP Requests
Modified: 7/8/2026
Fixes a bug in Zend Framework's Stream HTTP Wrapper
Modified: 7/8/2026
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`
Modified: 5/16/2026
OpenMage vulnerable to XSS in Admin Notifications
Modified: 11/6/2025
magento-lts Reset Password not protected against well-timed CSRF
Modified: 7/8/2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Modified: 5/16/2026
Data Flow Sanitation Issue Fix
Modified: 7/8/2026