Products: 1
Vulnerabilities: 4
Known Exploited: 0
1
Critical Level Threats
0
High Level Threats
2
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2025-10695
OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints
Last Modified: Dec 22, 2025
Published: Oct 03, 2025
CVE-2025-10696
OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list
Last Modified: Dec 22, 2025
Published: Oct 03, 2025
CVE-2025-10692
OpenSupports 4.11.0 — SQL Injection
Last Modified: Apr 15, 2026
Published: Oct 03, 2025
CVE-2023-48031
OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the attacker to execute arbitrary code or establish a reverse shell, leading to unauthorized file writes or control over the victim's station via a crafted file upload operation.
Last Modified: Sep 29, 2025
Published: Nov 17, 2023
Items Per Page
