Jpatokal maintains OpenFlights, a niche web-based flight data and route-tracking application, with observed vulnerabilities centered on cross-site scripting issues arising from improper input neutralization during web page generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jpatokal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41348MEDIUM openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php | Aug 29, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-41347MEDIUM openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php | Aug 29, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-41345MEDIUM openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php | Aug 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-41346MEDIUM openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php | Aug 29, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jpatokal.
Media articles that mention a CVE ID that affects a product developed by Jpatokal — matched by CVE ID, not by vendor name.