Openca develops public-key infrastructure and certificate-management software, a niche but security-critical domain where its products focus on PKI operations and certificate lifecycle management. The observed vulnerability surface centers on web-interface weaknesses including cross-site request forgery, typical of management and administrative tools exposed to internal networks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openca over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0004HIGH The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause | Feb 17, 2004 | 7.5 | 20 | NO | NO |
CVE-2008-0556HIGH Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users vi | Feb 19, 2008 | 7.5 | 19 | NO | NO |
CVE-2003-0960HIGH OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates. | Dec 15, 2003 | 7.5 | 19 | NO | NO |
CVE-2004-0787MEDIUM Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTM | Oct 20, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openca.
Media articles that mention a CVE ID that affects a product developed by Openca — matched by CVE ID, not by vendor name.