GHSA-5vrp-638w-p8m2 · Severity: medium · Ecosystem: composer — Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.
Conclusion & alert: CVE-2024-41676 is rated Low Risk (25.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.34%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.67% | 0.34% | -0.33% |
| 2 | 2026-03-04 | 0.44% | 0.67% | +0.23% |
| 3 | 2026-03-01 | — | 0.44% | — |
Full EPSS history (37 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.1 | 3.1 | MEDIUM |
|
2.3 | 1.4 | [email protected] |
| 4.8 | 3.1 | MEDIUM |
|
1.7 | 2.7 | [email protected] |
GHSA-5vrp-638w-p8m2 · Severity: medium · Ecosystem: composer — Magento LTS vulnerable to stored Cross-site Scripting (XSS) in admin system configs
| URL | Tags |
|---|---|
| https://github.com/OpenMage/magento-lts/commit/484cf8afc550e98bbf2c03fbb29a8450a32e7948 | Issue Tracking |
| https://github.com/OpenMage/magento-lts/security/advisories/GHSA-5vrp-638w-p8m2 | Mitigation Vendor Advisory |