All 5 CVE vulnerabilities found in OpenList, with AI-generated Chinese analysis, references, and POCs.
Vendor: OpenListTeam
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-69160 | OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API CWE-639 | 6.5 | Medium | 2026-08-18 |
| CVE-2026-73509 | OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal CWE-22 | 7.6 | High | 2026-08-13 |
| CVE-2026-25060 | OpenList Insecure TLS Default Configuration CWE-599 | 8.1 | High | 2026-02-02 |
| CVE-2026-25059 | OpenList affected by Path Traversal in file copy and remove handlers CWE-22 | 8.8 | High | 2026-02-02 |
| CVE-2025-50183 | OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer CWE-79 | 6.5 | Medium | 2025-06-19 |
All 5 known CVE vulnerabilities affecting OpenList with full Chinese analysis, references, and POCs where available.