Cale Dunlap maintains a focused product portfolio centered on the OpenInvoice application, a financial and billing management tool. The observed vulnerability signal concentrates around improper authentication mechanisms, a structural weakness class that recurs in this vendor's disclosures and carries implications for access control in financial systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cale Dunlap over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6523HIGH auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a | Mar 25, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6524MEDIUM resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be lev | Mar 25, 2009 | 6.5 | 26 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cale Dunlap.
Media articles that mention a CVE ID that affects a product developed by Cale Dunlap — matched by CVE ID, not by vendor name.