Openmediavault is a lightweight, open-source NAS and storage management platform that presents a focused but strategically exposed attack surface through its web-based administrative interface. Observed vulnerabilities cluster around server-side input handling and privilege management, particularly code injection, input validation, and cross-site scripting weaknesses that are characteristic of web applications managing system-level operations. Current severity, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openmediavault over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26124HIGH openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not use | Oct 2, 2020 | 8.8 | 76 | NO | YES |
CVE-2013-3632HIGH The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter. | Sep 29, 2014 | 8.8 | 73 | NO | YES |
CVE-2025-50674HIGH An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escala | Aug 22, 2025 | 7.8 | 28 | NO | NO |
CVE-2017-1000065MEDIUM Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary w | Jul 17, 2017 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openmediavault.
Media articles that mention a CVE ID that affects a product developed by Openmediavault — matched by CVE ID, not by vendor name.