Openfiler is a network storage appliance platform with a web-based management interface, where the durable vulnerability signal centers on input-handling issues in that management layer, specifically cross-site scripting and cross-site request forgery. Treat this as a focused vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openfiler over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-7190MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown | Sep 30, 2014 | 6.8 | 27 | NO | YES |
CVE-2011-1086MEDIUM Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter. | Feb 7, 2020 | 6.1 | 22 | NO | NO |
CVE-2023-49488MEDIUM A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the nic parameter | Dec 11, 2023 | 6.1 | 18 | NO | NO |
CVE-2014-4309MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 allow remote attackers to inject arbitrary web script or HTML via the (1) TinkerAjax parameter to uptime.html, | Jun 18, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openfiler.
Media articles that mention a CVE ID that affects a product developed by Openfiler — matched by CVE ID, not by vendor name.