Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

open-reception — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting open-reception. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerability data for the vendor open-reception, focusing on general software weakness classifications and associated security tags. It compiles a comprehensive collection of security issues affecting open-reception products, covering reported flaws from their initial disclosure through to the most recent updates. By reviewing this aggregated information, users can effectively track the vendor’s security advisories over time, gain a deeper understanding of specific weakness classes prevalent in their ecosystem, and examine the complete vulnerability history of individual products to assess long-term risk exposure. The content is organized to facilitate efficient analysis, allowing security professionals, developers, and auditors to identify patterns in reported defects and prioritize mitigation efforts based on the severity and prevalence of each issue. All entries are sourced from publicly available advisories and databases, ensuring transparency and reliability in the presented data. This resource serves as a centralized reference point for evaluating the security posture of open-reception software, helping stakeholders make informed decisions regarding patching, compliance, and product selection without relying on fragmented or incomplete information sources.

Found 16 results / 16 Clear Filters
Top products by open-reception: appointment-booking-software
CVE ID Title CVSS Severity Published
CVE-2026-48088 OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory — appointment-booking-software CWE-862 9.4 Critical 2026-08-06
CVE-2026-48087 OpenReception: WebAuthn passkey injection allows account takeover — appointment-booking-software CWE-287 9.8 Critical 2026-08-06
CVE-2026-48086 OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN — appointment-booking-software CWE-269 9.9 Critical 2026-08-06
CVE-2026-48085 OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap — appointment-booking-software CWE-862 9.8 Critical 2026-08-06
CVE-2026-48084 OpenReception doesn't rate limit passphrase login attempts — appointment-booking-software CWE-307 7.4 High 2026-08-06
CVE-2026-48083 OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits — appointment-booking-software CWE-117 6.5 Medium 2026-08-06
CVE-2026-48082 OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplification — appointment-booking-software CWE-770 3.7 Low 2026-08-06
CVE-2026-48081 OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer — appointment-booking-software CWE-79 8.1 High 2026-08-06
CVE-2026-48079 OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry — appointment-booking-software CWE-613 7.4 High 2026-08-06
CVE-2026-48078 OpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callers — appointment-booking-software CWE-200 5.3 Medium 2026-08-06
CVE-2026-48077 OpenReception: GET appointment by ID returns full appointment record without authorization — appointment-booking-software CWE-862 5.3 Medium 2026-08-06
CVE-2026-48076 OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channels — appointment-booking-software CWE-863 6.5 Medium 2026-08-06
CVE-2026-48075 OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injections — appointment-booking-software CWE-862 6.5 Medium 2026-08-06
CVE-2026-48074 OpenReception: Staff deletion removes pending invites cross-tenant by email match — appointment-booking-software CWE-863 2.7 Low 2026-08-06
CVE-2026-48071 OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-tenant lockout — appointment-booking-software CWE-307 5.8 Medium 2026-08-06
CVE-2026-48080 OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deployment — appointment-booking-software CWE-200 8.0 High 2026-08-06

This page lists every published CVE security advisory associated with open-reception. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.