Known Vulnerabilities for products from Opencats

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Opencats".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-27760 json Not Provided 2026-04-28 2026-04-28
CVE-2023-27295 json Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploi... 5.4 - MEDIUM 2023-02-28 2023-03-04
CVE-2023-27294 json Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted acco... 5.4 - MEDIUM 2023-02-28 2023-03-10
CVE-2023-27293 json Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript... 6.1 - MEDIUM 2023-02-28 2023-03-09
CVE-2023-27292 json An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET paramet... 5.4 - MEDIUM 2023-02-28 2023-03-04
CVE-2023-26847 json A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTM... 5.4 - MEDIUM 2023-04-11 2023-04-21
CVE-2023-26846 json A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTM... 5.4 - MEDIUM 2023-04-11 2023-04-21
CVE-2023-26845 json A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspec... 4.3 - MEDIUM 2023-04-11 2023-04-20
CVE-2022-48013 json Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.... 5.4 - MEDIUM 2023-01-27 2023-02-04
CVE-2022-48012 json Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/in... 6.1 - MEDIUM 2023-01-27 2023-02-04
CVE-2022-48011 json Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors f... 9.8 - CRITICAL 2023-01-27 2023-02-04
CVE-2022-43023 json OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors f... 6.5 - MEDIUM 2022-10-19 2022-10-20
CVE-2022-43022 json OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function. 6.5 - MEDIUM 2022-10-19 2022-10-20
CVE-2022-43021 json OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable. 6.5 - MEDIUM 2022-10-19 2022-10-20
CVE-2022-43020 json OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function. 6.5 - MEDIUM 2022-10-19 2022-10-20
CVE-2022-43019 json OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functio... 9.8 - CRITICAL 2022-10-19 2022-10-20
CVE-2022-43018 json OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the... 6.1 - MEDIUM 2022-10-19 2022-10-20
CVE-2022-43017 json OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component. 6.1 - MEDIUM 2022-10-19 2022-10-20
CVE-2022-43016 json OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component. 6.1 - MEDIUM 2022-10-19 2022-10-20
CVE-2022-43015 json OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage paramet... 6.1 - MEDIUM 2022-10-19 2022-10-20

Known software with vulnerabilities from Opencats

Type Vendor Product Version
ApplicationOpencatsOpencats-