Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opencats MEDIUM 5.4
CVE-2023-26846

A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Mitigation only
Fix from $1,600 2023-04-11
Opencats MEDIUM 5.4
CVE-2023-26847

A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Mitigation only
Fix from $1,600 2023-04-11
Opencats MEDIUM 6.1
CVE-2023-27293EPSS 57%

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a ques…

No fix yet
Fix from $1,600 2023-02-28
Opencats MEDIUM 5.4
CVE-2023-27292

An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

No fix yet
Fix from $1,600 2023-02-28
Opencats MEDIUM 5.4
CVE-2023-27294

Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious …

No fix yet
Fix from $1,600 2023-02-28
Opencats MEDIUM 5.4
CVE-2023-27295

Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating…

No fix yet
Fix from $1,600 2023-02-28
Opencats CRITICAL 9.8
CVE-2022-48011

Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

No fix yet
Fix from $2,300 2023-01-27
Opencats MEDIUM 6.1
CVE-2022-48012

Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=aja…

No fix yet
Fix from $1,600 2023-01-27
Opencats MEDIUM 5.4
CVE-2022-48013

Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vul…

No fix yet
Fix from $1,600 2023-01-27
Opencats MEDIUM 6.5
CVE-2022-43023

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

No fix yet
Fix from $1,600 2022-10-19
Opencats CRITICAL 9.8
CVE-2022-43019

OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

No fix yet
Fix from $2,300 2022-10-19
Opencats MEDIUM 6.5
CVE-2022-43020

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.

No fix yet
Fix from $1,600 2022-10-19
Opencats MEDIUM 6.5
CVE-2022-43021

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.

No fix yet
Fix from $1,600 2022-10-19
Opencats MEDIUM 6.5
CVE-2022-43022

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

No fix yet
Fix from $1,600 2022-10-19
Opencats MEDIUM 6.1
CVE-2022-43014

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.

No fix yet
Fix from $1,600 2022-10-19
Opencats MEDIUM 6.1
CVE-2022-43015

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.

No fix yet
Fix from $1,600 2022-10-19
Opencats MEDIUM 6.1
CVE-2022-43016

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.

No fix yet
Fix from $1,600 2022-10-19
Opencats MEDIUM 6.1
CVE-2022-43017

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

No fix yet
Fix from $1,600 2022-10-19
Opencats MEDIUM 6.1
CVE-2022-43018

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.

No fix yet
Fix from $1,600 2022-10-19
Opencats CRITICAL 9.8
CVE-2021-41560EPSS 11%

OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

Fix: after 0.9.6
Fix from $2,300 2021-12-15
Opencats MEDIUM 6.1
CVE-2021-25295

OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.

Fix: after 0.9.5-3
Fix from $1,600 2021-01-18
Opencats CRITICAL 9.8
CVE-2021-25294EPSS 11%

OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php …

Fix: after 0.9.5-3
Fix from $2,300 2021-01-18
Opencats HIGH 7.5
CVE-2019-13358EPSS 24%

lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker mus…

Fix: 0.9.4-3+
Fix from $1,950 2019-07-05