Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Openpanel-dev — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting Openpanel-dev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents security weaknesses and vulnerabilities associated with the Openpanel-dev vendor and its software ecosystem. It serves as a centralized resource for tracking security issues affecting products developed or maintained by this specific entity. The content herein aggregates reported vulnerabilities spanning multiple years, capturing the historical landscape of security flaws discovered in Openpanel-dev releases. The collection includes various weakness types, ranging from common input validation errors to complex architectural design flaws. The time range covers historical data from early adoption phases through to recent updates, ensuring a comprehensive view of the vendor’s security posture over time. This longitudinal data helps identify trends in code quality and response mechanisms. Visitors to this page can discover detailed information by tracking a vendor's advisories to see how Openpanel-dev addresses reported issues. You can also understand a weakness class by analyzing how specific vulnerabilities are exploited or mitigated within this vendor's context. Furthermore, users can look up a product's vulnerability history to assess risk levels and prioritize patching efforts. This resource is designed for security analysts, developers, and system administrators who need to evaluate the security impact of using Openpanel-dev technologies. By providing a structured overview of these issues, the page facilitates better decision-making regarding software procurement and maintenance. The information presented is intended for technical review and does not constitute security advice.

Top products by Openpanel-dev: openpanel
CVE ID Title CVSS Severity Published
CVE-2026-108579 OpenPanel through 2.3.0 CSV Formula Injection via Cohort Member Export — openpanel CWE-1236 4.2 Medium 2026-10-10
CVE-2026-93985 OpenPanel js-runtime through 2.3.0 JavaScript Template Sandbox Escape RCE — openpanel CWE-94 9.9 Critical 2026-09-19
CVE-2026-93983 OpenPanel through 2.3.0 SQL Injection via ClickHouse Property Key Filter — openpanel CWE-89 5.0 Medium 2026-09-19
CVE-2026-93984 OpenPanel API through 2.3.0 Authentication Bypass via Unverified Client Secret — openpanel CWE-287 5.3 Medium 2026-09-19
CVE-2026-93982 OpenPanel through 2.3.0 MCP Authentication Token in Query Parameter Logged Plaintext — openpanel CWE-532 3.3 Low 2026-09-19
CVE-2026-88893 OpenPanel through 2.3.0 Unauthenticated Share Lookup Information Disclosure — openpanel CWE-200 7.5 High 2026-09-10
CVE-2026-88891 OpenPanel through 2.3.0 Read-Only Access Level Enforcement Bypass via Mutations — openpanel CWE-269 8.3 High 2026-09-10
CVE-2026-88892 OpenPanel through 2.3.0 SSRF via Unguarded Importer File URL Fetch — openpanel CWE-918 5.0 Medium 2026-09-10
CVE-2026-88890 OpenPanel through 2.3.0 SQL Injection via unvalidated profile filter column identifier — openpanel CWE-89 8.5 High 2026-09-10
CVE-2026-85615 Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts — openpanel CWE-639 6.4 Medium 2026-09-04
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker — openpanel CWE-918 8.6 High 2026-09-04
CVE-2026-85613 OpenPanel before 2.3.0 Unauthenticated XSS via SVG Favicon Proxy — openpanel CWE-79 8.2 High 2026-09-04
CVE-2026-85612 OpenPanel before 2.3.0 SSRF via favicon and og endpoints — openpanel CWE-918 7.5 High 2026-09-04
CVE-2026-85611 OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures — openpanel CWE-639 6.4 Medium 2026-09-04
CVE-2026-85610 OpenPanel before 2.3.0 Remote Code Execution via chart formulas — openpanel CWE-94 8.8 High 2026-09-04
CVE-2026-85609 Openpanel before 2.3.0 SSRF via Site Checker Endpoint — openpanel CWE-918 7.5 High 2026-09-04
CVE-2026-77769 OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization Boundaries — openpanel CWE-639 6.5 Medium 2026-08-21
CVE-2026-77768 OpenPanel report.get Returns Any Report by Identifier Without Checking Project Access — openpanel CWE-639 6.5 Medium 2026-08-21

This page lists every published CVE security advisory associated with Openpanel-dev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.