Vulnerabilidades en Openpanel-dev

17 resultados
Análisis Vexday

Openpanel-dev apresenta 13 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando produto em fase de divulgação intensiva de riscos. Apesar de uma vulnerabilidade crítica, nenhuma está sob exploração ativa no momento. A fraqueza dominante (CWE-639 - Autorização em escopo errado) sugere falhas estruturais em controle de acesso que exigem atenção prioritária.

CVE-2026-93985CRITICALOpenPanel js-runtime JavaScript Template Sandbox Escape RCEEPSS 0.5%CVE-2026-85610HIGHOpenPanel before 2.3.0 Remote Code Execution via chart formulasEPSS 0.4%CVE-2026-88893HIGHOpenPanel Unauthenticated Share Lookup Information DisclosureEPSS 0.3%CVE-2026-85609MEDIUMOpenpanel before 2.3.0 SSRF via Site Checker EndpointEPSS 0.3%CVE-2026-88890HIGHOpenPanel SQL Injection via unvalidated profile filter column identifierEPSS 0.3%CVE-2026-88892MEDIUMOpenPanel SSRF via Unguarded Importer File URL FetchEPSS 0.3%CVE-2026-88891HIGHOpenPanel Read-Only Access Level Enforcement Bypass via MutationsEPSS 0.3%CVE-2026-77769HIGHOpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization BoundariesEPSS 0.2%CVE-2026-77768HIGHOpenPanel report.get Returns Any Report by Identifier Without Checking Project AccessEPSS 0.2%CVE-2026-85612HIGHOpenPanel before 2.3.0 SSRF via favicon and og endpointsEPSS 0.2%CVE-2026-85613HIGHOpenPanel Unauthenticated XSS via SVG Favicon ProxyEPSS 0.2%CVE-2026-93984MEDIUMOpenPanel API Authentication Bypass via Unverified Client SecretEPSS 0.2%CVE-2026-93983MEDIUMOpenPanel SQL Injection via ClickHouse Property Key FilterEPSS 0.2%CVE-2026-85611MEDIUMOpenPanel before 2.3.0 Cross-Tenant BOLA via report proceduresEPSS 0.2%CVE-2026-85614CRITICALOpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkerEPSS 0.2%CVE-2026-85615MEDIUMOpenpanel before 2.3.0 Cross-Tenant IDOR via report.getLayoutsEPSS 0.1%CVE-2026-93982MEDIUMOpenPanel MCP Authentication Token in Query Parameter Logged PlaintextEPSS 0.1%