Opencats
Opencats: vulnerabilidades y CVE
Opencats tiene 28 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses4
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-49490 | Alta (8.6) | 0.43% | — | 31 may 2026 | OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the… |
| CVE-2026-49489 | Alta (8.4) | 0.40% | — | 31 may 2026 | OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL… |
| CVE-2021-47936 | Crítica (9.3) | 0.66% | — | 10 may 2026 | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload… |
| CVE-2026-27760 | Crítica (9.2) | 3.4% | — | 28 abr 2026 | OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the… |
| CVE-2023-26847 | Media (5.4) | 0.43% | — | 11 abr 2023 | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates. |
| CVE-2023-26846 | Media (5.4) | 0.41% | — | 11 abr 2023 | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/index.php?m=candidates. |
| CVE-2023-26845 | Media (4.3) | 0.23% | — | 11 abr 2023 | A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors. |
| CVE-2023-27295 | Media (5.4) | 0.35% | — | 28 feb 2023 | Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating a dummy page that executes Javascript in an authenticated user's… |
| CVE-2023-27294 | Media (5.4) | 0.53% | — | 28 feb 2023 | Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious Javascript as the description for a calendar event, which would then… |
| CVE-2023-27293 | Media (6.1) | 57% | — | 28 feb 2023 | Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user… |
| CVE-2023-27292 | Media (5.4) | 1.0% | — | 28 feb 2023 | An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters. |
| CVE-2022-48013 | Media (5.4) | 0.52% | — | 27 ene 2023 | Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary web scripts or HTML… |
| CVE-2022-48012 | Media (6.1) | 1.4% | — | 27 ene 2023 | Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd. |
| CVE-2022-48011 | Crítica (9.8) | 1.1% | — | 27 ene 2023 | Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. |
| CVE-2022-43023 | Media (6.5) | 0.86% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. |
| CVE-2022-43022 | Media (6.5) | 0.86% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function. |
| CVE-2022-43021 | Media (6.5) | 0.86% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable. |
| CVE-2022-43020 | Media (6.5) | 0.86% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function. |
| CVE-2022-43019 | Crítica (9.8) | 2.1% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality. |
| CVE-2022-43018 | Media (6.1) | 1.5% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function. |
| CVE-2022-43017 | Media (6.1) | 1.5% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component. |
| CVE-2022-43016 | Media (6.1) | 1.5% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component. |
| CVE-2022-43015 | Media (6.1) | 1.4% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter. |
| CVE-2022-43014 | Media (6.1) | 1.4% | — | 19 oct 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter. |
| CVE-2021-41560 | Crítica (9.8) | 11% | — | 15 dic 2021 | OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. |
| CVE-2021-25295 | Media (6.1) | 1.5% | — | 18 ene 2021 | OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues. |
| CVE-2021-25294 | Crítica (9.8) | 11% | — | 18 ene 2021 | OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid… |
| CVE-2019-13358 | Alta (7.5) | 24% | — | 5 jul 2019 | lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.