Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openstamanager — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in openstamanager, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration vulnerabilities associated with the openstamanager product developed by OpenSTA. It serves as a centralized resource for security professionals and administrators seeking to understand the historical and current threat landscape surrounding this specific content management solution. The content on this page collects verified vulnerability records from multiple authoritative sources, including vendor advisories, public databases, and security research disclosures. The time range covered spans from the initial release of the software to the present day, ensuring that both legacy risks and recent findings are included for comprehensive analysis. Readers can discover critical insights by tracking vendor advisories to stay updated on patch availability and security updates issued by the openstamanager maintainers. Users can also understand a weakness class by examining common technical patterns and exploit mechanisms documented within the collected reports. Additionally, the page allows users to look up a product's vulnerability history to identify trends, such as frequent recurring issues in specific modules or versions. This approach facilitates better risk assessment and prioritization of remediation efforts for systems relying on openstamanager. The data is organized to highlight severity levels and affected versions, enabling administrators to quickly determine if their deployment is exposed to known exploits. By consolidating these disparate data points, the page provides a clear, actionable overview of the security posture related to openstamanager without requiring manual cross-referencing of multiple external sites.

Vendor: devcode-it

CVE ID Title CVSS Severity Published
CVE-2026-35470 OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals CWE-89 8.8 High 2026-04-06
CVE-2026-35168 OpenSTAManager: SQL Injection via Aggiornamenti Module CWE-89 8.8 High 2026-04-02
CVE-2026-28805 OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter CWE-89 8.8 High 2026-04-02
CVE-2026-29782 OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2 CWE-502 7.2 High 2026-04-02
CVE-2026-27012 Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php CWE-306 9.8 Critical 2026-03-03
CVE-2026-24415 OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter CWE-79 6.1AI Medium AI 2026-03-03
CVE-2025-69212 OpenSTAManager has an OS Command Injection in P7M File Processing CWE-78 8.8AI High AI 2026-02-06
CVE-2025-69214 OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint) CWE-89 8.8AI High AI 2026-02-06
CVE-2025-69216 OpenSTAManager has an SQL Injection in Scadenzario Print Template CWE-89 6.5AI Medium AI 2026-02-06
CVE-2026-24416 OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module CWE-89 9.1AI Critical AI 2026-02-06
CVE-2026-24417 OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service CWE-89 9.1AI Critical AI 2026-02-06
CVE-2026-24418 OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module CWE-89 8.1AI High AI 2026-02-06
CVE-2026-24419 OpenSTAManager has an SQL Injection in the Prima Nota module CWE-89 9.1AI Critical AI 2026-02-06
CVE-2025-69215 OpenSTAManager has an SQL Injection in the Stampe Module CWE-89 8.8AI High AI 2026-02-04
CVE-2025-69213 OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint) CWE-89 8.8AI High AI 2026-02-04
CVE-2025-65103 OpenSTAManager has an authenticated SQL Injection vulnerability in API via 'display' parameter CWE-89 8.8 High 2025-11-19

All 16 known CVE vulnerabilities affecting openstamanager with full Chinese analysis, references, and POCs where available.