Openstamanager
Devcode · 17 CVEs
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functional…
May 4, 2026
OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals
Apr 6, 2026
OpenSTAManager: SQL Injection via Aggiornamenti Module
Apr 2, 2026
OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter
Apr 2, 2026
OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2
Apr 2, 2026
Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php
Mar 3, 2026
OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter
Mar 3, 2026
OpenSTAManager has an OS Command Injection in P7M File Processing
Feb 6, 2026
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
Feb 6, 2026
OpenSTAManager has an SQL Injection in Scadenzario Print Template
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
Feb 6, 2026
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
Feb 6, 2026
OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module
Feb 6, 2026
OpenSTAManager has an SQL Injection in the Prima Nota module
Feb 6, 2026
OpenSTAManager has an SQL Injection in the Stampe Module
Feb 4, 2026
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
Feb 4, 2026
A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a re…
Sep 11, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-38751 | OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_module… | HIGH | 0.53% | May 4, 2026 |
| CVE-2026-35470 | OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals | HIGH | 0.49% | Apr 6, 2026 |
| CVE-2026-35168 | OpenSTAManager: SQL Injection via Aggiornamenti Module | HIGH | 0.81% | Apr 2, 2026 |
| CVE-2026-28805 | OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter | HIGH | 0.54% | Apr 2, 2026 |
| CVE-2026-29782 | OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2 | HIGH | 0.69% | Apr 2, 2026 |
| CVE-2026-27012 | Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php | CRITICAL | 0.67% | Mar 3, 2026 |
| CVE-2026-24415 | OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter | MEDIUM | 0.26% | Mar 3, 2026 |
| CVE-2025-69212 | OpenSTAManager has an OS Command Injection in P7M File Processing | CRITICAL | 1.94% | Feb 6, 2026 |
| CVE-2025-69214 | OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint) | HIGH | 0.47% | Feb 6, 2026 |
| CVE-2025-69216 | OpenSTAManager has an SQL Injection in Scadenzario Print Template | HIGH | 0.40% | Feb 6, 2026 |
| CVE-2026-24416 | OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module | HIGH | 0.41% | Feb 6, 2026 |
| CVE-2026-24417 | OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service | HIGH | 0.41% | Feb 6, 2026 |
| CVE-2026-24418 | OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module | HIGH | 0.40% | Feb 6, 2026 |
| CVE-2026-24419 | OpenSTAManager has an SQL Injection in the Prima Nota module | HIGH | 0.39% | Feb 6, 2026 |
| CVE-2025-69215 | OpenSTAManager has an SQL Injection in the Stampe Module | HIGH | 0.44% | Feb 4, 2026 |
| CVE-2025-69213 | OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint) | HIGH | 0.44% | Feb 4, 2026 |
| CVE-2023-38878 | A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaS… | MEDIUM | 0.77% | Sep 11, 2023 |
Showing 1 to 17 of 17 CVEs