OCS Inventory NG Ocsreports

5 known vulnerabilities in OCS Inventory NG Ocsreports, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-76178 CVSS 9.2 critical A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint…
  • CVE-2026-76177 CVSS 7.1 high Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the…
  • CVE-2026-76176 CVSS 8.6 high SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID…
  • CVE-2026-76175 CVSS 8.6 high SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an…
  • CVE-2026-76174 CVSS 9.4 critical Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application…