Products: 3
Vulnerabilities: 3
Known Exploited: 0
2
Critical Level Threats
0
High Level Threats
1
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2024-25738
A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configuration files to gain access to the administrator panel and achieve Remote Code Execution. A mitigating factor is that it requires the allow_url_include PHP runtime setting to be on, which is off in default installations. It also requires the /Upgrade route to be exposed, which is exposed by default after installing VuFind, and is recommended to be disabled by setting autoConfigure to false in config.ini.
Last Modified: Apr 15, 2026
Published: May 22, 2024
CVE-2024-23687
FOLIO mod-data-export-spring Hard-Coded Credentials
Last Modified: Nov 29, 2025
Published: Jan 19, 2024
CVE-2024-23685
FOLIO mod-remote-storage Hard Coded Credentials
Last Modified: Nov 29, 2025
Published: Jan 19, 2024
Items Per Page
