Openengine is a game engine framework with a narrow but structurally significant footprint, and its vulnerability exposure centers on input-validation and code-injection weaknesses typical of systems that parse and execute dynamic content. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openengine over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4329HIGH PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_c | Sep 30, 2008 | 10.0 | 36 | NO | YES |
CVE-2008-4719HIGH PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remote attackers to execute arbitra | Oct 23, 2008 | 9.3 | 33 | NO | YES |
CVE-2006-2280MEDIUM Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot d | May 10, 2006 | 5.0 | 23 | NO | YES |
CVE-2007-5035HIGH PHP remote file inclusion vulnerability in html/modules/extranet_profile/main.php in openEngine 1.9 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the thi | Sep 24, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openengine.
Media articles that mention a CVE ID that affects a product developed by Openengine — matched by CVE ID, not by vendor name.