Opensecurity's vulnerability footprint centers on a mobile security framework that sits prominently in the security-tooling landscape, where vulnerabilities tend toward serious outcomes. The recurring weaknesses—cross-site scripting, server-side request forgery, path traversal, and PHP remote file inclusion—reflect the framework's web-facing and server-side integration points and suggest exposure in input handling and file-access controls. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensecurity over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43399CRITICAL Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a f | Aug 19, 2024 | 9.8 | 32 | NO | NO |
CVE-2025-31116CRITICAL Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-202 | Mar 31, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-41955MEDIUM Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authenti | Jul 31, 2024 | 5.4 | 25 | NO | YES |
CVE-2022-41547HIGH Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability al | Oct 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-29190HIGH Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and | Mar 22, 2024 | 7.5 | 24 | NO | NO |
CVE-2025-58162MEDIUM MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any director | Sep 2, 2025 | 6.5 | 23 | NO | NO |
CVE-2023-42261HIGH Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because t | Sep 21, 2023 | 7.5 | 23 | NO | NO |
CVE-2026-33545MEDIUM MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string form | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2024-54000HIGH Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7 | Dec 3, 2024 | 7.5 | 21 | NO | NO |
CVE-2026-24490MEDIUM MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an a | Jan 27, 2026 | 4.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensecurity.
Media articles that mention a CVE ID that affects a product developed by Opensecurity — matched by CVE ID, not by vendor name.