Horizon
This hub aggregates every CVE we track for Horizon, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
61
CVEs tracked
0
Critical
11
High
0
In CISA KEV
Severity distribution
MEDIUM42HIGH11LOW6
Monthly trend
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
1
0
1
1
0
2
3
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Horizon.
- CVE-2026-89089OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)6.5
- CVE-2026-19596OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host5.9
- CVE-2026-89054OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes8.2
- CVE-2026-19182OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only4.3
- CVE-2026-19135OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes5.4
- CVE-2026-55748OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security harden...6.0
- CVE-2026-43002An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauth...5.3
- CVE-2026-22420WordPress Horizon theme <= 1.1 - Local File Inclusion vulnerability8.1
- CVE-2025-53122SQLi in OpenNMS Horizon and Meridian
- CVE-2025-53121Stored XSS in multiple 33.0.8files in opennms/opennms
- CVE-2023-40314Cross-site scripting in bootstrap.jsp5.8
- CVE-2023-40612Authenticated XXE Injection Via The File Editor5.3
- CVE-2022-45582Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.6.1
- CVE-2023-40315ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN5.3
- CVE-2023-40313Disable BeanShell Interpreter Remote Server Mode7.1
Product normalization is registry-driven with AI assist and human review. How it works