Ussd Gateway
Opencode · 6 CVEs
OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the we…
Mar 5, 2026
Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13…
Nov 26, 2025
Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6…
Nov 26, 2025
A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to…
Nov 26, 2025
OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID…
Nov 26, 2025
OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via…
Nov 26, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-70614 | OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authentic… | HIGH | 0.27% | Mar 5, 2026 |
| CVE-2025-65239 | Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level priv… | MEDIUM | 0.29% | Nov 26, 2025 |
| CVE-2025-65238 | Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level p… | MEDIUM | 0.34% | Nov 26, 2025 |
| CVE-2025-65237 | A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the cont… | MEDIUM | 0.27% | Nov 26, 2025 |
| CVE-2025-65236 | OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.p… | CRITICAL | 0.45% | Nov 26, 2025 |
| CVE-2025-65235 | OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByPr… | CRITICAL | 0.45% | Nov 26, 2025 |
Showing 1 to 6 of 6 CVEs