VendorsCRAWSopenatlasall versions
Vulnerabilities

CRAWS OpenAtlas

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2025-51536
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
Published 2025-08-04 · Analyzed
9.8EPSS 0.005
CVE-2025-51535
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.
Published 2025-08-04 · Analyzed
9.1EPSS 0.004
CVE-2025-60915
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request.
Published 2025-11-24 · Analyzed
8.1EPSS 0.004
CVE-2025-51534
A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.
Published 2025-08-04 · Analyzed
8.1EPSS 0.004
CVE-2025-60916
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter.
Published 2025-11-24 · Analyzed
5.4EPSS 0.002
CVE-2025-40702
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-40703
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-40704
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-40705
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-40706
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-40707
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-40708
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-40709
Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2025-56423
An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages
Published 2025-11-24 · Analyzed
5.3EPSS 0.003
CVE-2025-60917
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the color parameter.
Published 2025-11-24 · Analyzed
4.6EPSS 0.002
CVE-2025-60914
Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint.
Published 2025-11-24 · Analyzed
4.6EPSS 0.002