All 8 CVE vulnerabilities found in openreplay, with AI-generated Chinese analysis, references, and POCs.
Vendor: openreplay
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-57230 | OpenReplay: Authenticated ClickHouse SQL injection via session search CWE-89 | 5.4 | Medium | 2026-07-10 |
| CVE-2026-55881 | OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint CWE-639 | - | - | 2026-07-10 |
| CVE-2026-55880 | OpenReplay: Cross-user IDOR in notes and dashboard widgets CWE-639 | 7.1 | High | 2026-07-10 |
| CVE-2026-55879 | OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover CWE-79 | 9.3 | Critical | 2026-07-10 |
| CVE-2026-45296 | OpenReplay: Cross-tenant information disclosure in app_apikey projectKey routes via missing tenant binding CWE-284 | 7.7 | High | 2026-05-28 |
| CVE-2026-45297 | Cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch CWE-285 | - | - | 2026-05-28 |
| CVE-2026-28443 | OpenReplay: SQL injection in cards/search via unvalidated sort field parameter CWE-89 | 9.8 | - | 2026-03-05 |
| CVE-2023-48226 | OpenReplay HTML Injection vulnerability CWE-20 | 6.5 | Medium | 2023-11-21 |
All 8 known CVE vulnerabilities affecting openreplay with full Chinese analysis, references, and POCs where available.