Products: 3
Vulnerabilities: 26
Known Exploited: 0
2
Critical Level Threats
14
High Level Threats
8
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-42207
Magento LTS: Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` - magento-lts
Last Modified: May 17, 2026
Published: May 15, 2026
CVE-2026-42155
Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
Last Modified: May 17, 2026
Published: May 15, 2026
CVE-2026-42458
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Last Modified: May 17, 2026
Published: May 15, 2026
CVE-2026-40488
OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution
Last Modified: Apr 23, 2026
Published: Apr 20, 2026
CVE-2026-40098
OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant
Last Modified: Apr 23, 2026
Published: Apr 20, 2026
Items Per Page
