OpenNMS.org develops a network monitoring and management platform centered on its OpenNMS product, which serves as an operations-intelligence tool across enterprise and service-provider environments. The observed vulnerability pattern reflects the platform's role as a web-facing application, with the durable signal centered on cross-site scripting and related input-handling issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opennms.Org over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4320MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the j_username parameter to j_ace | Sep 29, 2008 | 4.3 | 21 | NO | YES |
CVE-2012-0936MEDIUM Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17, 1.9.93 and earlier, and 1. | Jan 29, 2012 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opennms.Org.
Media articles that mention a CVE ID that affects a product developed by Opennms.Org — matched by CVE ID, not by vendor name.