VYPR

Opennms

by Opennms

Source repositories

CVEs (15)

  • CVE-2026-89054HigSep 10, 2026
    risk 0.46cvss 8.2epss 0.01

    A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for…

  • CVE-2016-6556HigSep 24, 2021
    risk 0.46cvss 7.1epss 0.01

    OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an XSS payload which will trigger when a user of the web UI…

  • CVE-2016-6555HigSep 24, 2021
    risk 0.46cvss 7.1epss 0.01

    OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This…

  • CVE-2020-1652MedJul 17, 2020
    risk 0.36cvss 5.6epss 0.01

    OpenNMS is accessible via port 9443

  • CVE-2026-89089MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "Maintenance contracts expired"…

  • CVE-2021-25932MedJun 1, 2021
    risk 0.35cvss 5.4epss 0.01

    In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site…

  • CVE-2021-25935MedMay 25, 2021
    risk 0.35cvss 5.4epss 0.01

    In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site…

  • CVE-2026-19596MedSep 10, 2026
    risk 0.31cvss 5.9epss 0.00

    An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a source whose response is attacker-controlled (for example a compromised monitored host or an HTTP man-in-the-middle…

  • CVE-2026-19135MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can…

  • CVE-2026-19182MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm…

  • CVE-2008-4320Sep 29, 2008
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the j_username parameter to j_acegi_security_check, (2) the username parameter to notification/list.jsp, and (3) the filter…

  • CVE-2015-7856Oct 16, 2015
    risk 0.00cvss —epss 0.02

    OpenNMS has a default password of rtc for the rtc account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.

  • CVE-2014-3960Jun 4, 2014
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.12.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-0936Jan 29, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17, 1.9.93 and earlier, and 1.10.x before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via the Username…

  • CVE-2008-6095Feb 9, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in surveillanceView.htm in OpenNMS 1.5.94 allows remote attackers to inject arbitrary web script or HTML via the viewName parameter.