Opexustech develops government and enterprise compliance-management platforms, including e-case filing systems, FOIA request processing, and administrative audit solutions that handle sensitive regulatory workflows. The vendor's vulnerability footprint, concentrated across a small product portfolio, skews strongly toward critical-severity outcomes, reflecting the stakes of systems handling citizen records, legal filings, and regulatory compliance. The recurring weakness classes center on web-tier authorization and input-handling defects—cross-site scripting, authorization bypasses via user-controlled keys, improper authorization logic, and client-side enforcement gaps—that are characteristic of multi-tenant government platforms where access control boundaries must be strictly enforced. Defenders should treat updates to these platforms as urgent, particularly those addressing authentication and access-control flaws; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opexustech over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32865CRITICAL OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An att | Mar 19, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-32867CRITICAL OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPu | Mar 19, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-62586CRITICAL OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0. | Oct 16, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-58462CRITICAL OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete | Sep 9, 2025 | 9.8 | 31 | NO | NO |
CVE-2026-22234CRITICAL OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and do | Jan 8, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-22235HIGH OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any u | Jan 8, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-22230HIGH OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an | Jan 8, 2026 | 7.6 | 25 | NO | NO |
CVE-2025-54833HIGH OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brut | Jul 31, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-53553CRITICAL An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests. | Jan 16, 2025 | 9.1 | 24 | NO | NO |
CVE-2026-32869MEDIUM OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case information. An authenticated attacker | Mar 19, 2026 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opexustech.
Media articles that mention a CVE ID that affects a product developed by Opexustech — matched by CVE ID, not by vendor name.