Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openplcproject

First CVE: Apr 22, 2019Active for: 7 yearsTotal CVEs: 13
44.9
VTI Score
High

OpenPLC Project's vulnerability footprint concentrates in a small, specialized industrial control and automation product line that sits in the operationally critical tier of manufacturing and infrastructure environments. Vulnerabilities affecting the vendor skew toward serious outcomes, and recur through weakness classes including cross-site scripting, code injection, path traversal, and type-conversion flaws that are endemic to web-interfaced control systems and real-time embedded firmware. Defenders running OpenPLC deployments should treat advisories as high-priority due to the elevated severity tendency and the direct operational risk posed by these products; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openplcproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2019
7 years ago
Most Recent CVE
May 13, 2026
72 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-31630HIGH
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.
Aug 3, 20218.841NONO
CVE-2026-28205CRITICAL
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentic
Apr 9, 20269.832NONO
CVE-2018-20818CRITICAL
A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can c
Apr 22, 20199.831NONO
CVE-2024-34026CRITICAL
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially craf
Sep 18, 20249.830NONO
CVE-2026-35063HIGH
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators
Apr 9, 20268.827NONO
CVE-2026-31156MEDIUM
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validatio
May 13, 20266.526NONO
CVE-2026-35556HIGH
OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.
Apr 9, 20267.526NONO
CVE-2024-39590HIGH
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A special
Sep 18, 20247.521NONO
CVE-2024-39589HIGH
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A special
Sep 18, 20247.521NONO
CVE-2024-36981HIGH
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted
Sep 18, 20247.521NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
23%
54%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low5 (38.5%)
High0 (0.0%)
None8 (61.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openplcproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openplcproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openplcproject's Products

View all 3 CNAs →

Top CWEs