Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

openpanel — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in openpanel, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for openpanel, a product associated with the "openpanel" vendor tag. It collects security flaws affecting the openpanel platform across multiple weakness classes, covering disclosures from its initial release through the most recent advisories. Readers can use this section to track the vendor's security posture, understand recurring weakness patterns specific to openpanel, and review the product's vulnerability history without being overwhelmed by individual CVE entries.

Vendor: Openpanel-dev

CVE ID Title CVSS Severity Published
CVE-2026-108579 OpenPanel through 2.3.0 CSV Formula Injection via Cohort Member Export CWE-1236 4.2 Medium 2026-10-10
CVE-2026-93985 OpenPanel js-runtime through 2.3.0 JavaScript Template Sandbox Escape RCE CWE-94 9.9 Critical 2026-09-19
CVE-2026-93983 OpenPanel through 2.3.0 SQL Injection via ClickHouse Property Key Filter CWE-89 5.0 Medium 2026-09-19
CVE-2026-93984 OpenPanel API through 2.3.0 Authentication Bypass via Unverified Client Secret CWE-287 5.3 Medium 2026-09-19
CVE-2026-93982 OpenPanel through 2.3.0 MCP Authentication Token in Query Parameter Logged Plaintext CWE-532 3.3 Low 2026-09-19
CVE-2026-88893 OpenPanel through 2.3.0 Unauthenticated Share Lookup Information Disclosure CWE-200 7.5 High 2026-09-10
CVE-2026-88891 OpenPanel through 2.3.0 Read-Only Access Level Enforcement Bypass via Mutations CWE-269 8.3 High 2026-09-10
CVE-2026-88892 OpenPanel through 2.3.0 SSRF via Unguarded Importer File URL Fetch CWE-918 5.0 Medium 2026-09-10
CVE-2026-88890 OpenPanel through 2.3.0 SQL Injection via unvalidated profile filter column identifier CWE-89 8.5 High 2026-09-10
CVE-2026-85615 Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts CWE-639 6.4 Medium 2026-09-04
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker CWE-918 8.6 High 2026-09-04
CVE-2026-85613 OpenPanel before 2.3.0 Unauthenticated XSS via SVG Favicon Proxy CWE-79 8.2 High 2026-09-04
CVE-2026-85612 OpenPanel before 2.3.0 SSRF via favicon and og endpoints CWE-918 7.5 High 2026-09-04
CVE-2026-85611 OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures CWE-639 6.4 Medium 2026-09-04
CVE-2026-85610 OpenPanel before 2.3.0 Remote Code Execution via chart formulas CWE-94 8.8 High 2026-09-04
CVE-2026-85609 Openpanel before 2.3.0 SSRF via Site Checker Endpoint CWE-918 7.5 High 2026-09-04
CVE-2026-77769 OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization Boundaries CWE-639 6.5 Medium 2026-08-21
CVE-2026-77768 OpenPanel report.get Returns Any Report by Identifier Without Checking Project Access CWE-639 6.5 Medium 2026-08-21

All 18 known CVE vulnerabilities affecting openpanel with full Chinese analysis, references, and POCs where available.