Opensupports is a customer-support and ticketing platform with a focused product footprint, exhibiting vulnerability patterns centered on access control, server-side request forgery, and file-upload handling. The observed weakness classes reflect typical web-application boundaries where authorization logic, external-request validation, and input handling intersect; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensupports over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48031CRITICAL OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file | Nov 17, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-10696MEDIUM OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Le | Oct 3, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-10695MEDIUM Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'a | Oct 3, 2025 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensupports.
Media articles that mention a CVE ID that affects a product developed by Opensupports — matched by CVE ID, not by vendor name.