Openslides is a presentation and assembly-management platform deployed in conference, legislative, and event-coordination contexts, where its web-facing role and user-permission model create a characteristic attack surface. The vendor's vulnerability exposure clusters around input-handling and access-control weaknesses—including cross-site scripting, path traversal, privilege-escalation, and output-encoding flaws—that reflect the demands of a browser-delivered collaborative application. Vulnerabilities affecting this vendor skew toward serious outcomes; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openslides over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25519CRITICAL OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to version 4.2.29, OpenSlides suppo | Feb 4, 2026 | 9.8 | 29 | NO | NO |
CVE-2020-26280HIGH OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and elections of assemblies. OpenSlides version 3.2, due to unsufficie | Dec 18, 2020 | 8.9 | 27 | NO | NO |
CVE-2024-22893HIGH OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password | Sep 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-22892HIGH OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords. | Sep 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-30343MEDIUM A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download | Mar 21, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-30342MEDIUM An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the subm | Mar 21, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-30345MEDIUM An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements s | Mar 21, 2025 | 4.1 | 15 | NO | NO |
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the s | Mar 21, 2025 | 3.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openslides.
Media articles that mention a CVE ID that affects a product developed by Openslides — matched by CVE ID, not by vendor name.