Openpanel-dev openpanel
15 known vulnerabilities in Openpanel-dev openpanel, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-93985 CVSS 9.4 critical OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to…
- CVE-2026-93984 CVSS 6.9 medium OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering…
- CVE-2026-93983 CVSS 5.3 medium OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms…
- CVE-2026-93982 CVSS 4.8 medium OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs…
- CVE-2026-88893 CVSS 8.7 high OpenPanel through 2.3.0 share lookup procedures fail to validate access controls and return password hashes and protected report…
- CVE-2026-88892 CVSS 5.3 medium In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard…
- CVE-2026-88891 CVSS 7.2 high OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to…
- CVE-2026-88890 CVSS 8.4 high OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter…
- CVE-2026-85615 CVSS 5.3 medium Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC…
- CVE-2026-85614 CVSS 9.2 critical OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that…
- CVE-2026-85613 CVSS 8.4 high OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that…
- CVE-2026-85612 CVSS 8.7 high OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints…
- CVE-2026-85611 CVSS 5.3 medium OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and…
- CVE-2026-85610 CVSS 8.7 high OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to…
- CVE-2026-85609 CVSS 6.9 medium Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET…