Opencats
Vendor:
First CVE: Jul 5, 2019 · Active for 7 years
28
Total CVEs
More Total CVEs than 96% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Opencats over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 5, 2019
7 years ago
Most Recent CVE
May 31, 2026
56 days ago
CVE Severity & Scoring
Opencats28 CVEs
68%
14%
18%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None13 (46.4%)
Unknown0 (0.0%)
Required15 (53.6%)
Privileges Required
Low11 (39.3%)
High0 (0.0%)
None17 (60.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27760HIGH OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injec | Apr 28, 2026 | 8.1 | 61 | NO | YES |
CVE-2023-27293MEDIUM Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be e | Feb 28, 2023 | 6.1 | 49 | NO | NO |
CVE-2019-13358HIGH lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or | Jul 5, 2019 | 7.5 | 48 | NO | YES |
CVE-2021-47936CRITICAL OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resu | May 10, 2026 | 9.8 | 38 | NO | NO |
CVE-2021-41560CRITICAL OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. | Dec 15, 2021 | 9.8 | 36 | NO | NO |
CVE-2021-25294CRITICAL OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the param | Jan 18, 2021 | 9.8 | 36 | NO | NO |
CVE-2026-49489HIGH OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database content | May 31, 2026 | 8.5 | 35 | NO | NO |
CVE-2026-49490HIGH OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting | May 31, 2026 | 8.1 | 34 | NO | NO |
CVE-2022-43019CRITICAL OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality. | Oct 19, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-43016MEDIUM OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component. | Oct 19, 2022 | 6.1 | 31 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
8 CVEs
28.6% of CVEs· 98th percentile
ExploitDB
1 CVE
3.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Opencats
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.7 | 6 | 6.1 | 0.7% | 0 | 1 |
| 0.9.6 | 14 | 6.3 | 5.0% | 0 | 6 |