Onesignal

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-3155

    OneSignal – Web Push Notifications <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id'

    Last Modified: Apr 22, 2026
    Published: Apr 16, 2026

    CVE-2025-13950

    OneSignal – Web Push Notifications <= 3.6.1 - Missing Authorization to Unauthenticated Plugin Settings Update

    Last Modified: Apr 20, 2026
    Published: Dec 15, 2025

    CVE-2023-28430

    OneSignal repository github action command injection

    Last Modified: Feb 19, 2025
    Published: Mar 27, 2023

    CVE-2019-15827

    The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.

    Last Modified: Nov 21, 2024
    Published: Aug 30, 2019
    Items Per Page
    Onesignal Vulnerabilities & Security CVEs | CVE-DB