Open Audit is an asset discovery and compliance auditing platform deployed across IT infrastructure environments to catalog systems and validate configurations. While the product maintains a focused footprint, its role in access and inventory management creates exposure to authentication and access-control weaknesses that recur in its disclosure history. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Audit over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8979HIGH Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI. | Mar 25, 2018 | 8.8 | 38 | NO | YES |
CVE-2018-9137MEDIUM Open-AudIT before 2.2 has CSV Injection. | Apr 19, 2018 | 6.8 | 32 | NO | YES |
CVE-2018-8903MEDIUM Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen. | Mar 22, 2018 | 5.4 | 29 | NO | YES |
CVE-2018-9155MEDIUM Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demon | Apr 12, 2018 | 5.4 | 25 | NO | YES |
CVE-2018-8937MEDIUM An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A | Mar 26, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-8978MEDIUM Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI. | Mar 25, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Audit.
Media articles that mention a CVE ID that affects a product developed by Open Audit — matched by CVE ID, not by vendor name.