opencats CVE Vulnerabilities & Metrics

Focus on opencats vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About opencats Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with opencats. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total opencats CVEs: 24
Earliest CVE date: 05 Jul 2019, 21:15 UTC
Latest CVE date: 11 Apr 2023, 15:15 UTC

Latest CVE reference: CVE-2023-26847

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical opencats CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.22

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 20
4.0-6.9 2
7.0-8.9 0
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS opencats CVEs

These are the five CVEs with the highest CVSS scores for opencats, sorted by severity first and recency.

All CVEs for opencats

CVE-2023-26847 opencats vulnerability CVSS: 0 11 Apr 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates.

CVE-2023-26846 opencats vulnerability CVSS: 0 11 Apr 2023, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/index.php?m=candidates.

CVE-2023-26845 opencats vulnerability CVSS: 0 11 Apr 2023, 15:15 UTC

A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.

CVE-2023-27295 opencats vulnerability CVSS: 0 28 Feb 2023, 17:15 UTC

Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating a dummy page that executes Javascript in an authenticated user's session when visited.

CVE-2023-27294 opencats vulnerability CVSS: 0 28 Feb 2023, 17:15 UTC

Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious Javascript as the description for a calendar event, which would then be executed in other users' browsers if they browse to that event. This could result in stealing session tokens from users with higher permission levels or forcing users to make actions without their knowledge.

CVE-2023-27293 opencats vulnerability CVSS: 0 28 Feb 2023, 17:15 UTC

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.

CVE-2023-27292 opencats vulnerability CVSS: 0 28 Feb 2023, 17:15 UTC

An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

CVE-2022-48013 opencats vulnerability CVSS: 0 27 Jan 2023, 18:15 UTC

Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Title text fields.

CVE-2022-48012 opencats vulnerability CVSS: 0 27 Jan 2023, 18:15 UTC

Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.

CVE-2022-48011 opencats vulnerability CVSS: 0 27 Jan 2023, 18:15 UTC

Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

CVE-2022-43023 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

CVE-2022-43022 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVE-2022-43021 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.

CVE-2022-43020 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.

CVE-2022-43019 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

CVE-2022-43018 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.

CVE-2022-43017 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

CVE-2022-43016 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.

CVE-2022-43015 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.

CVE-2022-43014 opencats vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.

CVE-2021-41560 opencats vulnerability CVSS: 10.0 15 Dec 2021, 07:15 UTC

OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

CVE-2021-25295 opencats vulnerability CVSS: 4.3 18 Jan 2021, 06:15 UTC

OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.

CVE-2021-25294 opencats vulnerability CVSS: 10.0 18 Jan 2021, 06:15 UTC

OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object injection exploit chain can leverage an __destruct magic method in guzzlehttp.

CVE-2019-13358 opencats vulnerability CVSS: 5.0 05 Jul 2019, 21:15 UTC

lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.