Openstamanager
Vendor:
First CVE: Sep 11, 2023 · Active for 2 years
17
Total CVEs
More Total CVEs than 93% of tracked products
8.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openstamanager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2023
2 years ago
Most Recent CVE
May 4, 2026
81 days ago
CVE Severity & Scoring
Openstamanager17 CVEs
41%
53%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (88.2%)
Unknown0 (0.0%)
Required2 (11.8%)
Privileges Required
Low12 (70.6%)
High2 (11.8%)
None3 (17.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27012CRITICAL OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in | Mar 3, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-35470HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager c | Apr 6, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-35168HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains | Apr 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-28805HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable | Apr 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2025-69212HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M ( | Feb 6, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-38751HIGH OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php) | May 4, 2026 | 7.2 | 28 | NO | NO |
CVE-2025-69214HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endp | Feb 6, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-69213HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.p | Feb 4, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-69215HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module | Feb 4, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-29782HIGH OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated en | Apr 2, 2026 | 7.2 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Openstamanager
Top CWEs
Versions
No cataloged versions.