All 5 CVE vulnerabilities found in OpenBoxes, with AI-generated Chinese analysis, references, and POCs.
Vendor: n/a
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-14046 | OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted upload CWE-434 | 6.3 | Medium | 2026-08-18 |
| CVE-2024-14045 | OpenBoxes Product Supplier Edit Controller RoleInterceptor.groovy improper authorization CWE-285 | 6.3 | Medium | 2026-08-18 |
| CVE-2026-19929 | OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine CWE-1336 | 6.3 | Medium | 2026-08-16 |
| CVE-2026-19928 | OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management CWE-269 | 6.3 | Medium | 2026-08-16 |
| CVE-2026-19927 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery CWE-918 | 6.3 | Medium | 2026-08-16 |
All 5 known CVE vulnerabilities affecting OpenBoxes with full Chinese analysis, references, and POCs where available.