Open Realty is a real-estate listing and property-management platform with a focused vulnerability footprint concentrated in its primary product. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Realty over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5056MEDIUM Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open- | Sep 24, 2007 | 6.8 | 40 | NO | YES |
CVE-2012-1112MEDIUM Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_t | Sep 6, 2012 | 6.8 | 32 | NO | YES |
CVE-2006-3148HIGH SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php. | Jun 22, 2006 | 7.5 | 19 | NO | NO |
CVE-2011-3765MEDIUM Open-Realty 2.5.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstra | Sep 24, 2011 | 5.0 | 18 | NO | NO |
CVE-2007-0490MEDIUM index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action. | Jan 25, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Realty.
Media articles that mention a CVE ID that affects a product developed by Open Realty — matched by CVE ID, not by vendor name.