Getopensocial's vulnerability profile centers on its Open Social platform, a modestly represented but notably positioned social-networking and identity component in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur persistently across authorization and access-control weakness classes including missing authorization, improper access control, and cross-site request forgery that are characteristic of identity and social-graph systems. Defenders should prioritize patches for this vendor's disclosures given the severity tendency and the sensitive nature of identity and permission enforcement in social platforms; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getopensocial over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48921HIGH Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.14, from 12.4.0 befor | Jun 26, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-31685CRITICAL Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10. | Mar 31, 2025 | 9.1 | 24 | NO | NO |
CVE-2024-13241CRITICAL Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5. | Jan 9, 2025 | 9.1 | 24 | NO | NO |
CVE-2025-31686HIGH Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10. | Mar 31, 2025 | 8.1 | 22 | NO | NO |
CVE-2024-13240HIGH Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05. | Jan 9, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-13312MEDIUM Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9. | Jan 9, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-13273MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open S | Jan 9, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-13274MEDIUM Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 befo | Jan 9, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getopensocial.
Media articles that mention a CVE ID that affects a product developed by Getopensocial — matched by CVE ID, not by vendor name.