Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opexustech

First CVE: Jan 16, 2025Active for: 2 yearsTotal CVEs: 21
30.9
VTI Score
Low

Opexustech develops government and enterprise compliance-management platforms, including e-case filing systems, FOIA request processing, and administrative audit solutions that handle sensitive regulatory workflows. The vendor's vulnerability footprint, concentrated across a small product portfolio, skews strongly toward critical-severity outcomes, reflecting the stakes of systems handling citizen records, legal filings, and regulatory compliance. The recurring weakness classes center on web-tier authorization and input-handling defects—cross-site scripting, authorization bypasses via user-controlled keys, improper authorization logic, and client-side enforcement gaps—that are characteristic of multi-tenant government platforms where access control boundaries must be strictly enforced. Defenders should treat updates to these platforms as urgent, particularly those addressing authentication and access-control flaws; live severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opexustech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2025
18 months ago
Most Recent CVE
Mar 19, 2026
127 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-32865CRITICAL
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An att
Mar 19, 20269.832NONO
CVE-2026-32867CRITICAL
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPu
Mar 19, 20269.831NONO
CVE-2025-62586CRITICAL
OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.
Oct 16, 20259.831NONO
CVE-2025-58462CRITICAL
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete
Sep 9, 20259.831NONO
CVE-2026-22234CRITICAL
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and do
Jan 8, 20269.829NONO
CVE-2026-22235HIGH
OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any u
Jan 8, 20267.525NONO
CVE-2026-22230HIGH
OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an
Jan 8, 20267.625NONO
CVE-2025-54833HIGH
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brut
Jul 31, 20257.525NONO
CVE-2024-53553CRITICAL
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.
Jan 16, 20259.124NONO
CVE-2026-32869MEDIUM
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case information. An authenticated attacker
Mar 19, 20265.421NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
57%
14%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (52.4%)
Unknown0 (0.0%)
Required10 (47.6%)
Privileges Required
Low8 (38.1%)
High4 (19.0%)
None9 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opexustech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opexustech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opexustech's Products

View all 2 CNAs →

Top CWEs