Openwebanalytics

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-59397

    Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.

    Last Modified: Apr 15, 2026
    Published: Sep 15, 2025

    CVE-2022-24637

    Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

    Last Modified: Nov 21, 2024
    Published: Mar 18, 2022

    CVE-2014-2294

    Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.

    Last Modified: Nov 21, 2024
    Published: Apr 17, 2018

    CVE-2014-1457

    Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.

    Last Modified: Nov 21, 2024
    Published: Mar 20, 2018

    CVE-2014-1456

    Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web script or HTML via the owa_user_id parameter to index.php.

    Last Modified: Apr 12, 2025
    Published: Feb 28, 2014
    Items Per Page
    Openwebanalytics Vulnerabilities & Security CVEs | CVE-DB