Openplc
Openplc Runtime: vulnerabilities and CVEs
Openplc Runtime has 4 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months3
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71268 | Critical (9.9) | 0.58% | — | Aug 5, 2026 | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays… |
| CVE-2026-14480 | High (8.7) | 0.62% | — | Jul 10, 2026 | OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the… |
| CVE-2025-34226 | High (7.1) | 0.66% | — | Oct 3, 2025 | OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs… |
| CVE-2025-54962 | Medium (6.4) | 0.24% | — | Aug 4, 2025 | /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.