# CVE-2026-42458

## Summary

- **CVE ID:** CVE-2026-42458
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N)
- **CWE:** CWE-87
- **Published:** May 15, 2026
- **Last Modified:** May 15, 2026

## Description

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -> System -> Import/Export -> Dataflow - Profiles. This vulnerability is fixed in 20.18.0.

## Affected Products

- OpenMage — magento-lts (< 20.18.0)

## References

- [CNA](https://github.com/OpenMage/magento-lts/security/advisories/GHSA-x8jv-q8j2-487c)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._