Opendocman

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    1
    Critical Level Threats
    6
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-25684

    OpenDocMan 1.3.4 SQL Injection via where Parameter

    Last Modified: Apr 10, 2026
    Published: Apr 05, 2026

    CVE-2021-45834

    An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.

    Last Modified: Nov 21, 2024
    Published: Mar 18, 2022

    CVE-2014-1946

    OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.

    Last Modified: Nov 21, 2024
    Published: Apr 10, 2018

    CVE-2015-5625

    Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.

    Last Modified: Apr 12, 2025
    Published: Sep 07, 2015

    CVE-2014-4853

    Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file.

    Last Modified: Apr 12, 2025
    Published: Jul 10, 2014
    Items Per Page
    Opendocman Vulnerabilities & Security CVEs | CVE-DB