VendorsDevcodeopenstamanagerany version
Vulnerabilities

Devcode OpenSTAManager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-27012
Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php
Published 2026-03-03 · Analyzed
9.8EPSS 0.005
CVE-2025-69212
OpenSTAManager has an OS Command Injection in P7M File Processing
Published 2026-02-06 · Analyzed
9.4EPSS 0.020
CVE-2026-35168
OpenSTAManager: SQL Injection via Aggiornamenti Module
Published 2026-04-02 · Analyzed
8.8EPSS 0.007
CVE-2026-28805
OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter
Published 2026-04-02 · Analyzed
8.8EPSS 0.005
CVE-2025-69214
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
Published 2026-02-06 · Analyzed
8.8EPSS 0.004
CVE-2026-35470
OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals
Published 2026-04-06 · Analyzed
8.8EPSS 0.004
CVE-2025-69213
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
Published 2026-02-04 · Analyzed
8.8EPSS 0.004
CVE-2025-69215
OpenSTAManager has an SQL Injection in the Stampe Module
Published 2026-02-04 · Analyzed
8.8EPSS 0.004
CVE-2026-24417
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
Published 2026-02-06 · Analyzed
8.7EPSS 0.004
CVE-2026-24416
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
Published 2026-02-06 · Analyzed
8.7EPSS 0.004
CVE-2026-24418
OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module
Published 2026-02-06 · Analyzed
8.7EPSS 0.004
CVE-2025-69216
OpenSTAManager has an SQL Injection in Scadenzario Print Template
Published 2026-02-06 · Analyzed
8.7EPSS 0.004
CVE-2026-24419
OpenSTAManager has an SQL Injection in the Prima Nota module
Published 2026-02-06 · Analyzed
8.7EPSS 0.004
CVE-2026-29782
OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2
Published 2026-04-02 · Analyzed
7.2EPSS 0.006
CVE-2026-38751
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
Published 2026-05-04 · Analyzed
7.2EPSS 0.005
CVE-2023-38878
A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaScript in the web browser of a victim by injecting a malicious payload into the 'error' and 'error_description' parameters of 'oauth2.php'.
Published 2023-09-11 · Modified
6.1EPSS 0.008
CVE-2026-24415
OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter
Published 2026-03-03 · Analyzed
6.1EPSS 0.002