openmix records
2 published records for vendor openmix.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2026-37552No exploit | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17.openmix · mix php · CWE-502 | High8.4 | — | 0.5% | May 1, 2026 |
26Monitor | CVE-2026-42475No exploit | SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php.openmix · mix php · CWE-89 | Medium6.5 | — | 0.3% | May 1, 2026 |
- CVE-2026-3755233Monitor
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17.
HighCVSS 8.4No exploitEPSS 0%openmix · mix phpMay 1, 2026
- CVE-2026-4247526Monitor
SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php.
MediumCVSS 6.5No exploitEPSS 0%openmix · mix phpMay 1, 2026