Opensns is a niche open-source social networking platform with a focused vulnerability footprint centered on the core product and recurrent SQL injection weaknesses affecting its database query handling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensns over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21725CRITICAL OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid parameter. | Oct 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-14266HIGH OpenSNS v6.1.0 allows SQL Injection via the index.php?s=/ucenter/Config/ uid parameter because of the getNeedQueryData function in Application/Common/Model/UserModel.class.php. | Jul 25, 2019 | 8.8 | 25 | NO | NO |
CVE-2020-21726CRITICAL OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter. | Oct 7, 2021 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensns.
Media articles that mention a CVE ID that affects a product developed by Opensns — matched by CVE ID, not by vendor name.