Opplus maintains a narrowly scoped product footprint centered on Spring Boot Admin, a Java-based management and monitoring application. The vendor's vulnerability signal clusters around deserialization of untrusted data, input-validation issues, and injection weaknesses—including SQL injection—that are characteristic of Java framework applications handling dynamic configuration and user input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opplus over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3957CRITICAL A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main\resources\mapper\sys\SysLogDao | Apr 27, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-3413HIGH A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function | Apr 8, 2025 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opplus.
Media articles that mention a CVE ID that affects a product developed by Opplus — matched by CVE ID, not by vendor name.