VendorsBuffaloopen_xdmodany version
Vulnerabilities

Buffalo Open XDMoD any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-16988
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.
Published 2019-05-02 · Analyzed
9.8EPSS 0.016
CVE-2026-45779
Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromise
Published 2026-06-05 · Analyzed
9.8EPSS 0.009
CVE-2026-45777
Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injection
Published 2026-06-05 · Analyzed
9.8EPSS 0.007
CVE-2026-45778
Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset
Published 2026-06-05 · Analyzed
8.6EPSS 0.002
CVE-2018-16961
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the file parameter, allowing remote attackers to read PDF files in arbitrary directories.
Published 2019-05-02 · Modified
7.5EPSS 0.025
CVE-2018-16960
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal_name parameter.
Published 2019-05-02 · Modified
6.1EPSS 0.008
CVE-2026-45776
Open XDMoD has Broken Access Control via Client-Controlled Session Variable
Published 2026-06-05 · Analyzed
5.3EPSS 0.004