Opensupports

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-10695

    OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

    Last Modified: Dec 22, 2025
    Published: Oct 03, 2025

    CVE-2025-10696

    OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list

    Last Modified: Dec 22, 2025
    Published: Oct 03, 2025

    CVE-2025-10692

    OpenSupports 4.11.0 — SQL Injection

    Last Modified: Apr 15, 2026
    Published: Oct 03, 2025

    CVE-2023-48031

    OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the attacker to execute arbitrary code or establish a reverse shell, leading to unauthorized file writes or control over the victim's station via a crafted file upload operation.

    Last Modified: Sep 29, 2025
    Published: Nov 17, 2023
    Items Per Page
    Opensupports Vulnerabilities & Security CVEs | CVE-DB