CVE Tools

Opencats

19 CVEs tracked since 2021. Since Jan 2021, none of them reached CISA KEV.

Opencats CVEs per month

Jan 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Opencats CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0120
2021-022 or fewer
2021-03no snapshot
2021-042 or fewer
2021-052 or fewer
2021-062 or fewer
2021-072 or fewer
2021-083 or fewer
2021-092 or fewer
2021-102 or fewer
2021-112 or fewer
2021-122 or fewer
2022-012 or fewer
2022-022 or fewer
2022-033 or fewer
2022-043 or fewer
2022-053 or fewer
2022-063 or fewer
2022-073 or fewer
2022-083 or fewer
2022-093 or fewer
2022-10100
2022-113 or fewer
2022-123 or fewer
2023-0130
2023-0240
2023-03no snapshot
2023-043 or fewer
2023-053 or fewer
2023-064 or fewer
2023-073 or fewer
2023-084 or fewer
2023-093 or fewer
2023-104 or fewer
2023-114 or fewer
2023-124 or fewer
2024-014 or fewer
2024-024 or fewer
2024-034 or fewer
2024-044 or fewer
2024-055 or fewer
2024-064 or fewer
2024-074 or fewer
2024-084 or fewer
2024-093 or fewer
2024-104 or fewer
2024-114 or fewer
2024-123 or fewer
2025-014 or fewer
2025-023 or fewer
2025-035 or fewer
2025-044 or fewer
2025-054 or fewer
2025-064 or fewer
2025-075 or fewer
2025-084 or fewer
2025-094 or fewer
2025-104 or fewer
2025-114 or fewer
2025-125 or fewer
2026-015 or fewer
2026-025 or fewer
2026-037 or fewer
2026-046 or fewer
2026-057 or fewer
2026-067 or fewer
2026-077 or fewer
2026-088 or fewer
2026-099 or fewer

Products

The products that kept showing up in Opencats's monthly top three, with their CVEs summed over those months.

  1. Opencats194 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Opencats.

  1. CVE-2026-49490OpenCATS - SQL Injection in DataGrid Filter Handling for Tags Column8.1
  2. CVE-2026-49489OpenCATS - SQL Injection in DataGrid sortDirection Parameter8.5
  3. CVE-2021-47936OpenCATS 0.9.4 Remote Code Execution via Resume Upload9.8
  4. CVE-2026-27760OpenCATS PHP Code Injection via installer AJAX endpoint8.1
  5. CVE-2023-26847A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/in...5.4
  6. CVE-2023-26846A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/ind...5.4
  7. CVE-2023-26845A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.4.3
  8. CVE-2023-27293Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an a...6.1
  9. CVE-2023-27292An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.5.4
  10. CVE-2023-27294Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious Javascript as the description for a calendar eve...5.4
  11. CVE-2023-27295Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating a dummy page that executes Javascript in an aut...5.4
  12. CVE-2022-48013Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary...5.4
  13. CVE-2022-48011Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.9.8
  14. CVE-2022-48012Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.6.1
  15. CVE-2022-43014OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.6.1

The record

Peak rank
#68 in Oct 2022
Busiest month shown
Oct 2022, 10 CVEs
Months with a KEV entry
0 since Jan 2021
Monthly snapshots
4 since 2021
Opencats's full record, month by month