Opencode's vulnerability footprint centers on a USSD gateway product, a specialized telecommunications component that handles short message service interactions and sits in a trusted position within carrier networks. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across access-control and input-handling weakness classes—improper access control, SQL injection, and cross-site scripting—that are characteristic of web-facing authentication and data-processing systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opencode over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65236CRITICAL OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint. | Nov 26, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-65235CRITICAL OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function. | Nov 26, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-70614HIGH OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged a | Mar 5, 2026 | 8.1 | 26 | NO | NO |
CVE-2025-65238MEDIUM Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump use | Nov 26, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-65237MEDIUM A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's brows | Nov 26, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-65239MEDIUM Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server | Nov 26, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opencode.
Media articles that mention a CVE ID that affects a product developed by Opencode — matched by CVE ID, not by vendor name.