OpenPLC Project's vulnerability footprint concentrates in a small, specialized industrial control and automation product line that sits in the operationally critical tier of manufacturing and infrastructure environments. Vulnerabilities affecting the vendor skew toward serious outcomes, and recur through weakness classes including cross-site scripting, code injection, path traversal, and type-conversion flaws that are endemic to web-interfaced control systems and real-time embedded firmware. Defenders running OpenPLC deployments should treat advisories as high-priority due to the elevated severity tendency and the direct operational risk posed by these products; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openplcproject over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31630HIGH Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application. | Aug 3, 2021 | 8.8 | 41 | NO | NO |
CVE-2026-28205CRITICAL OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentic | Apr 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2018-20818CRITICAL A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can c | Apr 22, 2019 | 9.8 | 31 | NO | NO |
CVE-2024-34026CRITICAL A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially craf | Sep 18, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-35063HIGH OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators | Apr 9, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-31156MEDIUM A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validatio | May 13, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-35556HIGH OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information. | Apr 9, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-39590HIGH Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A special | Sep 18, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-39589HIGH Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A special | Sep 18, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-36981HIGH An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted | Sep 18, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openplcproject.
Media articles that mention a CVE ID that affects a product developed by Openplcproject — matched by CVE ID, not by vendor name.