Oplist develops the OpenList product, a modestly represented component in the vulnerability landscape whose disclosures center on path-traversal and certificate-validation weaknesses. These vulnerability classes reflect input-handling and cryptographic-trust boundaries that merit attention in products managing file access or network communications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oplist over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25059HIGH OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability in multiple file operation handlers in server/handles/fsman | Feb 2, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-25060HIGH OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsecureSkipVerify | Feb 2, 2026 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oplist.
Media articles that mention a CVE ID that affects a product developed by Oplist — matched by CVE ID, not by vendor name.