Public Knowledge Project

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    8
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-13469

    Public Knowledge Project omp/ojs Payment Instructions Setting paymentForm.tpl cross site scripting

    Last Modified: Apr 15, 2026
    Published: Nov 20, 2025

    CVE-2024-7902

    pkp ojs signOut redirect

    Last Modified: Aug 20, 2024
    Published: Aug 17, 2024

    CVE-2024-25438

    A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.

    Last Modified: May 15, 2025
    Published: Mar 01, 2024

    CVE-2022-26616

    PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.

    Last Modified: Nov 21, 2024
    Published: Apr 04, 2022

    CVE-2022-24181

    Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

    Last Modified: Nov 21, 2024
    Published: Apr 01, 2022
    Items Per Page