Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Open ISES — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting Open ISES. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page provides vulnerability aggregation data for the vendor Open ISES, focusing on general software weakness types. It compiles a comprehensive collection of security issues affecting Open ISES products, covering reported vulnerabilities from their initial disclosure through to recent updates. By aggregating this information, the page serves as a centralized resource for understanding the security landscape surrounding this specific vendor's software ecosystem. Visitors can use this resource to track the vendor's security advisories over time, gaining insight into how quickly and effectively they respond to emerging threats. The data allows users to understand the prevalence and nature of specific weakness classes within Open ISES implementations, helping to contextualize the risk profile of their systems. Furthermore, individuals can look up a particular product's vulnerability history to assess its long-term security posture and identify recurring patterns in reported flaws. This structured approach facilitates better risk management and informed decision-making for administrators and security analysts responsible for maintaining Open ISES environments. The content is presented neutrally to support technical analysis rather than promotional evaluation.

Top products by Open ISES: Tickets Open ISES Project
CVE ID Title CVSS Severity Published
CVE-2018-25404 The Open ISES Project 3.30A SQL Injection via add_facnote.php — Open ISES Project CWE-89 8.2 High 2026-05-29
CVE-2018-25403 The Open ISES Project 3.30A SQL Injection via city_graph.php — Open ISES Project CWE-89 8.2 High 2026-05-29
CVE-2018-25402 The Open ISES Project 3.30A SQL Injection via inc_types_graph.php — Open ISES Project CWE-89 8.2 High 2026-05-29
CVE-2018-25401 The Open ISES Project 3.30A SQL Injection via sever_graph.php — Open ISES Project CWE-89 8.2 High 2026-05-29
CVE-2018-25399 The Open ISES Project 3.30A SQL Injection via nearby.php — Open ISES Project CWE-89 8.2 High 2026-05-29
CVE-2018-25400 The Open ISES Project 3.30A SQL Injection via form_post.php — Open ISES Project CWE-89 8.2 High 2026-05-29
CVE-2018-25398 The Open ISES Project 3.30A SQL Injection via main.php — Open ISES Project CWE-89 8.2 High 2026-05-29
CVE-2026-48249 Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in rm/incs/mobile_login.inc.php — Tickets CWE-295 5.9 Medium 2026-05-21
CVE-2026-48248 Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/login.inc.php — Tickets CWE-295 5.9 Medium 2026-05-21
CVE-2026-48247 Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/functions.inc.php — Tickets CWE-295 5.9 Medium 2026-05-21
CVE-2026-48246 Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in ajax/reports.php — Tickets CWE-295 5.9 Medium 2026-05-21
CVE-2026-48245 Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in tables.php — Tickets CWE-798 5.3 Medium 2026-05-21
CVE-2026-48244 Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.php — Tickets CWE-798 5.3 Medium 2026-05-21
CVE-2026-48243 Open ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.php — Tickets CWE-798 5.3 Medium 2026-05-21
CVE-2026-48242 Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in import_mdb.php — Tickets CWE-798 8.1 High 2026-05-21
CVE-2026-48241 Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in loader.php — Tickets CWE-798 8.1 High 2026-05-21
CVE-2026-48240 Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48239 Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48238 Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48237 Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48236 Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48235 Open ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External GPS Tracker Data — Tickets CWE-89 8.2 High 2026-05-21
CVE-2026-48234 Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir Parameters — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48233 Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Parameter — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48232 Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48231 Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters — Tickets CWE-89 7.1 High 2026-05-21
CVE-2026-48230 Open ISES Tickets < 3.44.2 Reflected XSS via ticketsmdb_import.php Multiple POST Parameters — Tickets CWE-79 5.4 Medium 2026-05-21
CVE-2026-48229 Open ISES Tickets < 3.44.2 Reflected XSS via routes_i.php ticket_id Parameter — Tickets CWE-79 5.4 Medium 2026-05-21
CVE-2026-48228 Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id Parameters — Tickets CWE-79 5.4 Medium 2026-05-21
CVE-2026-48227 Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id Parameters — Tickets CWE-79 5.4 Medium 2026-05-21

This page lists every published CVE security advisory associated with Open ISES. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.