Devcode
Devcode Openstamanager: vulnerabilidades y CVE
Devcode Openstamanager tiene 18 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses17
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-38751 | Alta (7.2) | 0.53% | — | 4 may 2026 | OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php) |
| CVE-2026-35470 | Alta (8.8) | 0.49% | — | 6 abr 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injection vulnerability.… |
| CVE-2026-35168 | Alta (8.8) | 0.81% | — | 2 abr 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature… |
| CVE-2026-29782 | Alta (7.2) | 0.69% | — | 2 abr 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It… |
| CVE-2026-28805 | Alta (8.8) | 0.54% | — | 2 abr 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blind SQL Injection… |
| CVE-2026-27012 | Crítica (9.8) | 0.67% | — | 3 mar 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to… |
| CVE-2026-24415 | Media (5.1) | 0.26% | — | 3 mar 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The… |
| CVE-2026-24418 | Alta (8.7) | 0.38% | — | 6 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler… |
| CVE-2026-24417 | Alta (8.7) | 0.39% | — | 6 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the global search… |
| CVE-2026-24416 | Alta (8.7) | 0.39% | — | 6 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Time-Based Blind SQL Injection vulnerability in the article pricing… |
| CVE-2025-69216 | Alta (8.7) | 0.38% | — | 6 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an authenticated SQL injection vulnerability in OpenSTAManager's Scadenzario (Payment Schedule) print… |
| CVE-2025-69214 | Alta (8.7) | 0.44% | — | 6 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endpoint when handling the componenti… |
| CVE-2025-69212 | Crítica (9.4) | 2.0% | — | 6 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (signed XML) file decoding… |
| CVE-2026-24419 | Alta (8.7) | 0.36% | — | 6 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the Prima Nota (Journal Entry)… |
| CVE-2025-69215 | Alta (8.7) | 0.40% | — | 4 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module. At time of publication, no known… |
| CVE-2025-69213 | Alta (8.7) | 0.40% | — | 4 feb 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.php endpoint when handling the get_sedi… |
| CVE-2025-65103 | Alta (8.8) | 0.34% | — | 19 nov 2025 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerability in the API allows any user, regardless of permission… |
| CVE-2023-38878 | Media (6.1) | 0.77% | — | 11 sept 2023 | A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaScript in the web browser of a victim by injecting a… |