Openx operates a digital advertising and exchange platform whose vulnerability profile concentrates in its core ad-tech application and recurs through web-layer input-handling flaws including SQL injection, cross-site scripting, path traversal, and cross-site request forgery, alongside authentication weaknesses typical of complex user-facing services. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility and prevalence of the web-application attack surface. Defenders should prioritize timely patching of this vendor's releases and treat ad-tech infrastructure as an attack vector for supply-chain compromise; current severity, exploitation, and remediation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openx over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4211CRITICAL A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP | Feb 14, 2020 | 9.8 | 84 | NO | YES |
CVE-2009-4098MEDIUM Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arb | Nov 29, 2009 | 6.0 | 44 | NO | YES |
CVE-2013-5954MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delet | Apr 25, 2014 | 6.8 | 34 | NO | YES |
CVE-2013-7376MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the authentication of administrators, a | May 14, 2014 | 6.8 | 31 | NO | YES |
CVE-2009-0291HIGH Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter. | Jan 27, 2009 | 7.5 | 31 | NO | YES |
CVE-2008-6163HIGH SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter. | Feb 20, 2009 | 7.5 | 28 | NO | YES |
CVE-2012-4989MEDIUM Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the pare | Oct 22, 2012 | 4.3 | 24 | NO | YES |
CVE-2013-7149HIGH SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows re | Dec 28, 2013 | 7.5 | 23 | NO | NO |
CVE-2012-4990HIGH SQL injection vulnerability in admin/campaign-zone-link.php in OpenX 2.8.10 before revision 81823 allows remote attackers to execute arbitrary SQL commands via the ids[] parameter | Oct 22, 2012 | 7.5 | 23 | NO | NO |
CVE-2013-3514MEDIUM Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot dot) in the group parameter to | May 14, 2014 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openx.
Media articles that mention a CVE ID that affects a product developed by Openx — matched by CVE ID, not by vendor name.