Openpsa2 is a business management and customer relations platform whose vulnerability footprint concentrates in its core openpsa product, with the observed exposure centered on data-handling and serialization weaknesses including untrusted deserialization and XML injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpsa2 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000525CRITICAL openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information disclosure and remote code execution. Thi | Jun 26, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-1000526HIGH Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service. This attack appear to be exploitable via Specially crafted XM | Jun 26, 2018 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpsa2.
Media articles that mention a CVE ID that affects a product developed by Openpsa2 — matched by CVE ID, not by vendor name.