Openpages
Vendor:
First CVE: Jul 9, 2025 · Active for 1 year
6
Total CVEs
More Total CVEs than 80% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
4.8
Avg CVSS
Higher Avg CVSS than 6% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openpages over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 9, 2025
12 months ago
Most Recent CVE
Nov 12, 2025
255 days ago
CVE Severity & Scoring
Openpages6 CVEs
17%
83%
All CVEs352,708 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low5 (83.3%)
High0 (0.0%)
None1 (16.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-36223MEDIUM IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attack | Nov 12, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-33110MEDIUM IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web | Nov 6, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-36121MEDIUM IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's | Oct 27, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-27368MEDIUM IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user inter | Nov 12, 2025 | 4.3 | 17 | NO | NO |
IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system. | Sep 15, 2025 | 3.3 | 16 | NO | NO |
CVE-2025-2670MEDIUM IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points related to workflow feature of | Jul 9, 2025 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Openpages
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.0 | 5 | 4.9 | 0.2% | 0 | 0 |
| 9.0.0 | 4 | 5.3 | 0.2% | 0 | 0 |