Openreplay

Openreplay

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 10.07.2026 20:47:31
  • Zuletzt bearbeitet 13.07.2026 19:21:55

OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy enabled built ClickHouse queries by inserting user input into the query string, including two positions ...

  • EPSS 0.25%
  • Veröffentlicht 10.07.2026 20:44:15
  • Zuletzt bearbeitet 13.07.2026 19:21:55

OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAccess checke...

  • EPSS 0.2%
  • Veröffentlicht 10.07.2026 20:42:15
  • Zuletzt bearbeitet 13.07.2026 19:21:55

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id a...

  • EPSS 0.29%
  • Veröffentlicht 10.07.2026 20:39:44
  • Zuletzt bearbeitet 13.07.2026 18:12:29

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding,...

  • EPSS 0.23%
  • Veröffentlicht 28.05.2026 16:51:47
  • Zuletzt bearbeitet 28.05.2026 18:40:37

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API key itself is valid and that the target projectKey...

  • EPSS 0.21%
  • Veröffentlicht 28.05.2026 16:50:38
  • Zuletzt bearbeitet 28.05.2026 18:40:37

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS api/auth/auth_project.py:14-38 and EE ee/api/auth/...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 05.03.2026 20:53:17
  • Zuletzt bearbeitet 17.03.2026 15:45:31

OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sort.field parameter. This issue has been patched in version 1.20.0.

Exploit
  • EPSS 0.78%
  • Veröffentlicht 21.11.2023 20:15:07
  • Zuletzt bearbeitet 21.11.2024 08:31:15

OpenReplay is a self-hosted session replay suite. In version 1.14.0, due to lack of validation Name field - Account Settings (for registration looks like validation is correct), a bad actor can send emails with HTML injected code to the victims. Bad ...