Openpanel-dev
- Products in analyzed data
- 1
- Catalog vulnerabilities
- 13
Severity across 13 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 13 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 13 vulnerability records associated with Openpanel-dev.
Among the 13 records analyzed by CyStack, 9 are High or Critical and 0 appear in the CISA KEV catalog for priority remediation.
The list below is based on vulnerabilities that have been viewed and analyzed; it does not represent the complete global vulnerability corpus. Use the product filter to narrow the scope.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-88893OpenPanel Unauthenticated Share Lookup Information Disclosure | Exploitation statusNot known exploited | FixYes | Affected productopenpanel | Published09/10/2026 | SeverityHigh |
CVE-2026-88892OpenPanel SSRF via Unguarded Importer File URL Fetch | Exploitation statusPublic exploit | FixYes | Affected productopenpanel | Published09/10/2026 | SeverityMedium |
CVE-2026-88891OpenPanel Read-Only Access Level Enforcement Bypass via Mutations | Exploitation statusNot confirmed | FixYes | Affected productopenpanel | Published09/10/2026 | SeverityHigh |
CVE-2026-88890OpenPanel SQL Injection via unvalidated profile filter column identifier | Exploitation statusNot confirmed | FixYes | Affected productopenpanel | Published09/10/2026 | SeverityHigh |
CVE-2026-85615Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts | Exploitation statusNot known exploited | FixYes | Affected productopenpanel | Published09/04/2026 | SeverityMedium |
CVE-2026-85614OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | Exploitation statusNot known exploited | FixYes | Affected productopenpanel | Published09/04/2026 | SeverityCritical |
CVE-2026-85613OpenPanel Unauthenticated XSS via SVG Favicon Proxy | Exploitation statusPublic exploit | FixYes | Affected productopenpanel | Published09/04/2026 | SeverityHigh |
CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpoints | Exploitation statusNot confirmed | FixYes | Affected productopenpanel | Published09/04/2026 | SeverityHigh |
CVE-2026-85611OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures | Exploitation statusPublic exploit | FixYes | Affected productopenpanel | Published09/04/2026 | SeverityMedium |
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulas | Exploitation statusNot known exploited | FixYes | Affected productopenpanel | Published09/04/2026 | SeverityHigh |
CVE-2026-85609Openpanel before 2.3.0 SSRF via Site Checker Endpoint | Exploitation statusPublic exploit | FixYes | Affected productopenpanel | Published09/04/2026 | SeverityMedium |
CVE-2026-77769OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization Boundaries | Exploitation statusPublic exploit | FixYes | Affected productopenpanel | Published08/21/2026 | SeverityHigh |
CVE-2026-77768OpenPanel report.get Returns Any Report by Identifier Without Checking Project Access | Exploitation statusPublic exploit | FixYes | Affected productopenpanel | Published08/21/2026 | SeverityHigh |