Openbi maintains a focused business-intelligence and analytics platform whose vulnerability profile concentrates on a single product core and skews strongly toward critical-severity outcomes. The recurring weakness classes—file-upload validation failures, unsafe deserialization, access-control flaws, code injection, and OS command injection—reflect the attack surface of web-facing data-processing and scripting functionality typical of analytics platforms. Defenders should prioritize patching for this vendor and restrict network exposure of its platform; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openbi over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1032CRITICAL A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Data | Jan 30, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-1116CRITICAL A vulnerability was found in openBI up to 1.0.8. It has been classified as critical. Affected is the function index of the file /application/plugins/controller/Upload.php. The mani | Jan 31, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-1113CRITICAL A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnity of the file /application/index/controller/Unity.php. The m | Jan 31, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-1035CRITICAL A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /application/index/controller/Icon.p | Jan 30, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-1115CRITICAL A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function dlfile of the file /application/websocket/controller/Setting.php. The ma | Jan 31, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-1114CRITICAL A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /application/index/controller/Screen.php | Jan 31, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-1036CRITICAL A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index/controller/Screen.php of the c | Jan 30, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-1034CRITICAL A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The man | Jan 30, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-1198CRITICAL A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component | Feb 3, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-1117CRITICAL A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /application/index/controller/Sc | Jan 31, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openbi.
Media articles that mention a CVE ID that affects a product developed by Openbi — matched by CVE ID, not by vendor name.