CVE-2023-23617: Openmage Magento

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds.

Affected products

  • Openmage Magento: before 19.4.22 (fixed in 19.4.22); from 20.0.0, before 20.0.19 (fixed in 20.0.19)

Published 2023-01-28. Last modified 2026-06-17.