Opensourcebms develops an open-source background management system where disclosed vulnerabilities center on critical application-layer weaknesses: code injection and missing authentication controls for sensitive functions. This niche product's vulnerability profile reflects typical exposure patterns for administrative software where code execution and authentication bypass represent the primary attack surface; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensourcebms over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9082HIGH ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_ | Feb 24, 2019 | 8.8 | 99 | YES | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensourcebms.
Media articles that mention a CVE ID that affects a product developed by Opensourcebms — matched by CVE ID, not by vendor name.