CVE-2025-27400: Magento LTS vulnerable to stored XSS in theme config fields
As reported by Aakash Adhikari, Github: @justlife4x4, the Design > Themes > Skin (Images / CSS) config field allows a Stored XSS when it contains an end script tag.
References
- github.com/OpenMage/magento-lts
- github.com/OpenMage/magento-lts/commit/d307e5bf75729a2347dde0952fe9fd9fcd9c6aea
- github.com/OpenMage/magento-lts/releases/tag/v20.12.3
- github.com/OpenMage/magento-lts/releases/tag/v20.13.0
- github.com/OpenMage/magento-lts/security/advisories/GHSA-5pxh-89cx-4668
- github.com/advisories/GHSA-5pxh-89cx-4668
- nvd.nist.gov/vuln/detail/CVE-2025-27400
Detect and mitigate CVE-2025-27400 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →