Openmediavault

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-52102

    OpenMediaVault openmediavault-md Plugin Command Injection Leading to Root Execution

    Last Modified: Aug 13, 2026
    Published: Aug 03, 2026

    CVE-2025-50674

    An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.

    Last Modified: Sep 12, 2025
    Published: Aug 22, 2025

    CVE-2020-26124

    openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.

    Last Modified: Nov 21, 2024
    Published: Oct 02, 2020

    CVE-2017-1000065

    Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.

    Last Modified: Apr 20, 2025
    Published: Jul 13, 2017

    CVE-2013-3632

    The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.

    Last Modified: Apr 12, 2025
    Published: Sep 29, 2014
    Items Per Page
    Openmediavault Vulnerabilities & Security CVEs | CVE-DB