Openads is a niche ad-serving platform product with a focused vulnerability footprint centered on code-injection weaknesses, reflecting the risks inherent to dynamic content generation and ad-delivery mechanics. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openads over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0635HIGH Unspecified vulnerability in the delivery engine in Openads 2.4.0 through 2.4.2 allows remote attackers to execute arbitrary PHP code via unknown vectors. | Feb 6, 2008 | 7.5 | 28 | NO | NO |
CVE-2007-2046HIGH Multiple CRLF injection vulnerabilities in adclick.php in (a) Openads (phpAdsNew) 2.0.11 and earlier and (b) Openads for PostgreSQL (phpPgAds) 2.0.11 and earlier allow remote attac | Apr 16, 2007 | 7.5 | 21 | NO | NO |
CVE-2007-2047HIGH CRLF injection vulnerability in www/delivery/ck.php in Openads 2.3 (aka Max Media Manager, MMM) before 0.3.31-alpha-pr3 allows remote attackers to inject arbitrary HTTP headers and | Apr 16, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-0477MEDIUM Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 | Jan 25, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-0363MEDIUM Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote | Jan 19, 2007 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openads.
Media articles that mention a CVE ID that affects a product developed by Openads — matched by CVE ID, not by vendor name.