Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-6w5f-mgxj-c7mw |
|
MINI-6w5f-mgxj-c7mw |
| MINI-4xrw-3jqg-9wgq |
|
MINI-4xrw-3jqg-9wgq |
| MINI-59vq-vf5w-3rhx |
|
MINI-59vq-vf5w-3rhx |
| MINI-99m3-2g95-28j3 |
|
MINI-99m3-2g95-28j3 |
| MINI-4gh3-6qch-78xm |
|
MINI-4gh3-6qch-78xm |
| MINI-43c3-8m26-58xf |
|
MINI-43c3-8m26-58xf |
| MINI-x924-rgj7-vhrw |
|
MINI-x924-rgj7-vhrw |
| MINI-xx7m-5fhc-mxpp |
|
MINI-xx7m-5fhc-mxpp |
| MINI-3w9x-pwjj-9jv5 |
|
MINI-3w9x-pwjj-9jv5 |
| MINI-j9f7-4vfv-wjm9 |
|
MINI-j9f7-4vfv-wjm9 |
| MINI-jv5m-fjc2-8m2g |
|
MINI-jv5m-fjc2-8m2g |
| MINI-qrvp-88jx-wwjq |
|
MINI-qrvp-88jx-wwjq |
| MINI-xvxc-mjc7-7f3g |
|
MINI-xvxc-mjc7-7f3g |
| MINI-q7v6-6p3r-wfh8 |
|
MINI-q7v6-6p3r-wfh8 |
| MINI-75hj-wvpg-xx49 |
|
MINI-75hj-wvpg-xx49 |
| GHSA-p73f-w79w-jqr5 |
|
Authorization Flaw in openclaw (GHSA-p73f-w79w-jqr5)
vulnerability in openclaw (GHSA-p73f-w79w-jqr5). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.6` or later.
|
| GHSA-j472-gf56-x589 |
|
Vulnerability in openclaw (GHSA-j472-gf56-x589)
vulnerability in openclaw (GHSA-j472-gf56-x589). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.12` or later.
|
| GHSA-77q5-rr5v-x43q |
|
Vulnerability in openclaw (GHSA-77q5-rr5v-x43q)
vulnerability in openclaw (GHSA-77q5-rr5v-x43q). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.7` or later.
|
| GHSA-w5ww-7chg-mxcq |
|
Authorization Flaw in openclaw (GHSA-w5ww-7chg-mxcq)
vulnerability in openclaw (GHSA-w5ww-7chg-mxcq). Risk of unauthorized operations or information disclosure. Exploitable via ``commands.allowFrom``. Mitigation: upgrade to `2026.5.6` or later.
|
| CVE-2026-50185 |
|
Vulnerability in cmov (CVE-2026-50185)
vulnerability in cmov (CVE-2026-50185). Risk of unauthorized operations or information disclosure. Exploitable via ``Cmov``. Mitigation: upgrade to `0.5.4` or later.
|
| CVE-2026-8699 |
|
Cross-Site Scripting (XSS) in CVE-2026-8699 (CVE-2026-8699)
cross-site scripting in CVE-2026-8699 (CVE-2026-8699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55952 |
|
Vulnerability in erlang (CVE-2026-55952)
vulnerability in erlang (CVE-2026-55952). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55950 |
|
Vulnerability in dos (CVE-2026-55950)
vulnerability in dos (CVE-2026-55950). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54891 |
|
Vulnerability in erlang (CVE-2026-54891)
vulnerability in erlang (CVE-2026-54891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54887 |
|
Vulnerability in erlang (CVE-2026-54887)
vulnerability in erlang (CVE-2026-54887). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54886 |
|
Vulnerability in dos (CVE-2026-54886)
vulnerability in dos (CVE-2026-54886). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53422 |
|
Vulnerability in erlang (CVE-2026-53422)
vulnerability in erlang (CVE-2026-53422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50282 |
|
Vulnerability in craftcms/cms (CVE-2026-50282)
vulnerability in craftcms/cms (CVE-2026-50282). Risk of unauthorized operations or information disclosure. Exploitable via ``deleteAssets``. Mitigation: upgrade to `4.17.14` or later.
|
| CVE-2026-50281 |
|
Vulnerability in craftcms/cms (CVE-2026-50281)
vulnerability in craftcms/cms (CVE-2026-50281). Risk of unauthorized operations or information disclosure. Exploitable via ``newAttributes``. Mitigation: upgrade to `5.9.21` or later.
|
| CVE-2024-58352 |
|
Vulnerability in CVE-2024-58352 (CVE-2024-58352)
vulnerability in CVE-2024-58352 (CVE-2024-58352). Confidential information can be exposed externally.
|
| CVE-2024-14037 |
|
Unrestricted File Upload in CVE-2024-14037 (CVE-2024-14037)
vulnerability in CVE-2024-14037 (CVE-2024-14037). Successful exploitation can lead to full system takeover.
|
| CVE-2022-50973 |
|
Unrestricted File Upload in CVE-2022-50973 (CVE-2022-50973)
vulnerability in CVE-2022-50973 (CVE-2022-50973). Successful exploitation can lead to full system takeover.
|
| MINI-5697-9fqg-6779 |
|
MINI-5697-9fqg-6779 |
| CVE-2026-50149 |
|
Vulnerability in github.com/projectcontour/contour (CVE-2026-50149)
vulnerability in github.com/projectcontour/contour (CVE-2026-50149). Confidential information can be exposed externally. Exploitable via ``HTTPProxy``. Mitigation: upgrade to `1.33.5` or later.
|
| MINI-f67w-wpx7-xmwm |
|
MINI-f67w-wpx7-xmwm |
| MINI-x96x-qh8f-49cj |
|
MINI-x96x-qh8f-49cj |
| MINI-cgf6-3j6c-qr24 |
|
MINI-cgf6-3j6c-qr24 |
| MINI-gg79-r5mh-4jxx |
|
MINI-gg79-r5mh-4jxx |
| MINI-pwqj-cx8v-8x69 |
|
MINI-pwqj-cx8v-8x69 |
| MINI-f982-53j6-4r56 |
|
MINI-f982-53j6-4r56 |
| MINI-276x-g45r-j6cx |
|
MINI-276x-g45r-j6cx |
| GHSA-4m3v-q747-pc6h |
|
Vulnerability in openclaw (GHSA-4m3v-q747-pc6h)
vulnerability in openclaw (GHSA-4m3v-q747-pc6h). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.4.24` or later.
|
| MINI-wccx-qg9h-663j |
|
MINI-wccx-qg9h-663j |
| MINI-hr2v-fc7q-j8vq |
|
MINI-hr2v-fc7q-j8vq |
| GHSA-275c-xpvc-jgfw |
|
Vulnerability in openclaw (GHSA-275c-xpvc-jgfw)
vulnerability in openclaw (GHSA-275c-xpvc-jgfw). Risk of unauthorized operations or information disclosure. Exploitable via ``secrets.reload``. Mitigation: upgrade to `2026.4.22` or later.
|
| GHSA-3wqp-prf6-2m72 |
|
Vulnerability in openclaw (GHSA-3wqp-prf6-2m72)
vulnerability in openclaw (GHSA-3wqp-prf6-2m72). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.6` or later.
|
| GHSA-6c4r-g249-wv3c |
|
Vulnerability in openclaw (GHSA-6c4r-g249-wv3c)
vulnerability in openclaw (GHSA-6c4r-g249-wv3c). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.4.26` or later.
|
| MINI-h32j-r6pw-h8wf |
|
MINI-h32j-r6pw-h8wf |
| MINI-q6p2-r67p-r8px |
|
MINI-q6p2-r67p-r8px |
| MINI-jmpm-mxj4-8f5j |
|
MINI-jmpm-mxj4-8f5j |