« Volver al listado

Opencats

Opencats: vulnerabilidades y CVE

Opencats tiene 28 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE28
Últimos 12 meses4
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-49490Alta (8.6)0.43%—31 may 2026
OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the…
CVE-2026-49489Alta (8.4)0.40%—31 may 2026
OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL…
CVE-2021-47936Crítica (9.3)0.66%—10 may 2026
OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload…
CVE-2026-27760Crítica (9.2)3.4%—28 abr 2026
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the…
CVE-2023-26847Media (5.4)0.43%—11 abr 2023
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates.
CVE-2023-26846Media (5.4)0.41%—11 abr 2023
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/index.php?m=candidates.
CVE-2023-26845Media (4.3)0.23%—11 abr 2023
A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.
CVE-2023-27295Media (5.4)0.35%—28 feb 2023
Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating a dummy page that executes Javascript in an authenticated user's…
CVE-2023-27294Media (5.4)0.53%—28 feb 2023
Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious Javascript as the description for a calendar event, which would then…
CVE-2023-27293Media (6.1)57%—28 feb 2023
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user…
CVE-2023-27292Media (5.4)1.0%—28 feb 2023
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.
CVE-2022-48013Media (5.4)0.52%—27 ene 2023
Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary web scripts or HTML…
CVE-2022-48012Media (6.1)1.4%—27 ene 2023
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.
CVE-2022-48011Crítica (9.8)1.1%—27 ene 2023
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
CVE-2022-43023Media (6.5)0.86%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
CVE-2022-43022Media (6.5)0.86%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.
CVE-2022-43021Media (6.5)0.86%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.
CVE-2022-43020Media (6.5)0.86%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.
CVE-2022-43019Crítica (9.8)2.1%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
CVE-2022-43018Media (6.1)1.5%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.
CVE-2022-43017Media (6.1)1.5%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
CVE-2022-43016Media (6.1)1.5%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
CVE-2022-43015Media (6.1)1.4%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
CVE-2022-43014Media (6.1)1.4%—19 oct 2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
CVE-2021-41560Crítica (9.8)11%—15 dic 2021
OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.
CVE-2021-25295Media (6.1)1.5%—18 ene 2021
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
CVE-2021-25294Crítica (9.8)11%—18 ene 2021
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid…
CVE-2019-13358Alta (7.5)24%—5 jul 2019
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System2
  2. T1059 Command and Scripting Interpreter2
  3. T1190 Exploit Public-Facing Application2
  4. T1210 Exploitation of Remote Services2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.