Devcode's vulnerability profile centers on OpenStaManager, a modestly represented business management and invoicing application that recurs with a meaningful share of serious-severity disclosures. The durable weakness classes affecting the product span web application input handling and authentication boundaries, including SQL injection, cross-site scripting, OS command injection, unsafe deserialization, and missing authentication controls—patterns typical of server-side PHP applications with evolving security maturity. Defenders deploying this application should prioritize patching for injection and authentication classes and restrict network exposure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Devcode over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27012CRITICAL OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in | Mar 3, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-35470HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager c | Apr 6, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-35168HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains | Apr 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-28805HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable | Apr 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2025-69212HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M ( | Feb 6, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-38751HIGH OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php) | May 4, 2026 | 7.2 | 28 | NO | NO |
CVE-2025-69214HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endp | Feb 6, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-69213HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.p | Feb 4, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-69215HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module | Feb 4, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-29782HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated en | Apr 2, 2026 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Devcode.
Media articles that mention a CVE ID that affects a product developed by Devcode — matched by CVE ID, not by vendor name.