devcode records
17 published records for vendor devcode.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 29.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-306 Missing Authentication for Critical Function1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-502 Deserialization of Untrusted Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-27012No exploit | Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.phpdevcode · openstamanager · CWE-306 | Critical9.8 | — | 0.6% | Mar 3, 2026 |
38Monitor | CVE-2025-69212Proof of concept | OpenSTAManager has an OS Command Injection in P7M File Processingdevcode · openstamanager · CWE-78 | Critical9.4 | — | 2.0% | Feb 6, 2026 |
35Monitor | CVE-2026-35168No exploit | OpenSTAManager: SQL Injection via Aggiornamenti Moduledevcode · openstamanager · CWE-89 | High8.8 | — | 0.8% | Apr 2, 2026 |
35Monitor | CVE-2026-28805No exploit | OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameterdevcode · openstamanager · CWE-89 | High8.8 | — | 0.5% | Apr 2, 2026 |
35Monitor | CVE-2026-35470No exploit | OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modalsdevcode · openstamanager · CWE-89 | High8.8 | — | 0.5% | Apr 6, 2026 |
34Monitor | CVE-2025-69214Proof of concept | OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)devcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 6, 2026 |
34Monitor | CVE-2025-69213Proof of concept | OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)devcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 4, 2026 |
34Monitor | CVE-2025-69215Proof of concept | OpenSTAManager has an SQL Injection in the Stampe Moduledevcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 4, 2026 |
34Monitor | CVE-2026-24416Proof of concept | OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Moduledevcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 6, 2026 |
34Monitor | CVE-2026-24417Proof of concept | OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Servicedevcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 6, 2026 |
34Monitor | CVE-2026-24418Proof of concept | OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations moduledevcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 6, 2026 |
34Monitor | CVE-2025-69216Proof of concept | OpenSTAManager has an SQL Injection in Scadenzario Print Templatedevcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 6, 2026 |
34Monitor | CVE-2026-24419Proof of concept | OpenSTAManager has an SQL Injection in the Prima Nota moduledevcode · openstamanager · CWE-89 | High8.7 | — | 0.4% | Feb 6, 2026 |
28Monitor | CVE-2026-29782Proof of concept | OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2devcode · openstamanager · CWE-502 | High7.2 | — | 0.7% | Apr 2, 2026 |
28Monitor | CVE-2026-38751Proof of concept | OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornadevcode · openstamanager · CWE-434 | High7.2 | — | 0.5% | May 4, 2026 |
24Monitor | CVE-2023-38878No exploit | A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execdevcode · openstamanager · CWE-79 | Medium6.1 | — | 0.8% | Sep 11, 2023 |
20Monitor | CVE-2026-24415Proof of concept | OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameterdevcode · openstamanager · CWE-79 | Medium5.1 | — | 0.2% | Mar 3, 2026 |
- CVE-2026-2701239Monitor
Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php
CriticalCVSS 9.8No exploitEPSS 1%devcode · openstamanagerMar 3, 2026
- CVE-2025-6921238Monitor
OpenSTAManager has an OS Command Injection in P7M File Processing
CriticalCVSS 9.4Proof of conceptEPSS 2%devcode · openstamanagerFeb 6, 2026
- CVE-2026-3516835Monitor
OpenSTAManager: SQL Injection via Aggiornamenti Module
HighCVSS 8.8No exploitEPSS 1%devcode · openstamanagerApr 2, 2026
- CVE-2026-2880535Monitor
OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter
HighCVSS 8.8No exploitEPSS 1%devcode · openstamanagerApr 2, 2026
- CVE-2026-3547035Monitor
OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals
HighCVSS 8.8No exploitEPSS 0%devcode · openstamanagerApr 6, 2026
- CVE-2025-6921434Monitor
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 6, 2026
- CVE-2025-6921334Monitor
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 4, 2026
- CVE-2025-6921534Monitor
OpenSTAManager has an SQL Injection in the Stampe Module
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 4, 2026
- CVE-2026-2441634Monitor
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 6, 2026
- CVE-2026-2441734Monitor
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 6, 2026
- CVE-2026-2441834Monitor
OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 6, 2026
- CVE-2025-6921634Monitor
OpenSTAManager has an SQL Injection in Scadenzario Print Template
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 6, 2026
- CVE-2026-2441934Monitor
OpenSTAManager has an SQL Injection in the Prima Nota module
HighCVSS 8.7Proof of conceptEPSS 0%devcode · openstamanagerFeb 6, 2026
- CVE-2026-2978228Monitor
OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2
HighCVSS 7.2Proof of conceptEPSS 1%devcode · openstamanagerApr 2, 2026
- CVE-2026-3875128Monitor
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiorna
HighCVSS 7.2Proof of conceptEPSS 1%devcode · openstamanagerMay 4, 2026
- CVE-2023-3887824Monitor
A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to exec
MediumCVSS 6.1No exploitEPSS 1%devcode · openstamanagerSep 11, 2023
- CVE-2026-2441520Monitor
OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter
MediumCVSS 5.1Proof of conceptEPSS 0%devcode · openstamanagerMar 3, 2026