A fork of Magento-1 that is accepting bug fixes (backward compatible, drop in replacement for official Magento)
93%
Total Score
80
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-40488 New openmage/magento-lts is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 20.16.0. | 0.0.0 - 20.16.0 | High |
CVE-2026-40098 New openmage/magento-lts is vulnerable to Missing Authorization in versions 0.0.0 - 20.17.0. | 0.0.0 - 20.17.0 | Medium |
CVE-2026-25525 New openmage/magento-lts is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 20.17.0. | 0.0.0 - 20.17.0 | Medium |
CVE-2026-25524 New openmage/magento-lts is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 20.17.0. | 0.0.0 - 20.17.0 | High |
CVE-2026-25523 openmage/magento-lts is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 20.16.1. | 0.0.0 - 20.16.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
pelago/emogrifier Version ^7.0 | — | — |
shardj/zf1-future Version 1.24.0 | — | — |
ezyang/htmlpurifier Version ^4.17 | — | — |
phpseclib/phpseclib Version ^3.0.14 | — | — |
symfony/polyfill-php74 Version ^1.29 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant