CVE-2026-93985
- EPSS 0.48%
- Veröffentlicht 19.09.2026 11:53:37
- Zuletzt bearbeitet 02.10.2026 15:17:13
OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates...
CVE-2026-93984
- EPSS 0.2%
- Veröffentlicht 19.09.2026 11:53:36
- Zuletzt bearbeitet 02.10.2026 15:17:12
OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and ...
CVE-2026-93983
- EPSS 0.2%
- Veröffentlicht 19.09.2026 11:53:35
- Zuletzt bearbeitet 02.10.2026 15:17:12
OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
CVE-2026-85615
- EPSS 0.14%
- Veröffentlicht 04.09.2026 11:30:10
- Zuletzt bearbeitet 10.09.2026 16:17:59
Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitra...
CVE-2026-85609
- EPSS 0.29%
- Veröffentlicht 04.09.2026 11:30:06
- Zuletzt bearbeitet 08.09.2026 20:18:59
Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query parame...
CVE-2026-77769
- EPSS 0.24%
- Veröffentlicht 21.08.2026 11:05:15
- Zuletzt bearbeitet 23.09.2026 17:17:42
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied ...
CVE-2026-77768
- EPSS 0.24%
- Veröffentlicht 21.08.2026 11:05:14
- Zuletzt bearbeitet 23.09.2026 17:17:41
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries a proje...
CVE-2025-25872
- EPSS 0.26%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 03.04.2025 15:35:07
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
- EPSS 0.44%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 03.04.2025 15:36:00
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
CVE-2024-53584
- EPSS 4.11%
- Veröffentlicht 31.01.2025 17:15:15
- Zuletzt bearbeitet 23.05.2025 15:57:32
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.