Openreception
Openreception Appointment Booking Software: vulnerabilidades y CVE
Openreception Appointment Booking Software tiene 16 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses16
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54460 | Crítica (9.8) | 0.70% | — | 17 sept 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an… |
| CVE-2026-48088 | Crítica (9.4) | 0.38% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores… |
| CVE-2026-48087 | Crítica (9.8) | 0.57% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the… |
| CVE-2026-48086 | Crítica (9.9) | 0.44% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT… |
| CVE-2026-48084 | Alta (7.4) | 0.39% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong… |
| CVE-2026-48083 | Media (6.5) | 0.36% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema… |
| CVE-2026-48082 | Baja (3.7) | 0.39% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at… |
| CVE-2026-48081 | Alta (8.1) | 0.24% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration… |
| CVE-2026-48080 | Alta (8) | 0.47% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any… |
| CVE-2026-48079 | Alta (7.4) | 0.50% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler… |
| CVE-2026-48078 | Media (5.3) | 0.34% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived… |
| CVE-2026-48077 | Media (5.3) | 0.43% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no… |
| CVE-2026-48076 | Media (6.5) | 0.33% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns… |
| CVE-2026-48075 | Media (6.5) | 0.42% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without… |
| CVE-2026-48074 | Baja (2.7) | 0.29% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying… |
| CVE-2026-48071 | Media (5.8) | 0.40% | — | 6 ago 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.