Skip to content
Noroxi

devcode records

17 published records for vendor devcode.

All records

17 records
  • Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php

    CriticalCVSS 9.8No exploitEPSS 1%

    devcode · openstamanagerMar 3, 2026

  • OpenSTAManager has an OS Command Injection in P7M File Processing

    CriticalCVSS 9.4Proof of conceptEPSS 2%

    devcode · openstamanagerFeb 6, 2026

  • OpenSTAManager: SQL Injection via Aggiornamenti Module

    HighCVSS 8.8No exploitEPSS 1%

    devcode · openstamanagerApr 2, 2026

  • OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter

    HighCVSS 8.8No exploitEPSS 1%

    devcode · openstamanagerApr 2, 2026

  • OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals

    HighCVSS 8.8No exploitEPSS 0%

    devcode · openstamanagerApr 6, 2026

  • OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 6, 2026

  • OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 4, 2026

  • OpenSTAManager has an SQL Injection in the Stampe Module

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 4, 2026

  • OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 6, 2026

  • OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 6, 2026

  • OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 6, 2026

  • OpenSTAManager has an SQL Injection in Scadenzario Print Template

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 6, 2026

  • OpenSTAManager has an SQL Injection in the Prima Nota module

    HighCVSS 8.7Proof of conceptEPSS 0%

    devcode · openstamanagerFeb 6, 2026

  • OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2

    HighCVSS 7.2Proof of conceptEPSS 1%

    devcode · openstamanagerApr 2, 2026

  • OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiorna

    HighCVSS 7.2Proof of conceptEPSS 1%

    devcode · openstamanagerMay 4, 2026

  • A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to exec

    MediumCVSS 6.1No exploitEPSS 1%

    devcode · openstamanagerSep 11, 2023

  • OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter

    MediumCVSS 5.1Proof of conceptEPSS 0%

    devcode · openstamanagerMar 3, 2026