VYPR

Openatlas

by Austrian Archaeological Institute

CVEs (7)

  • CVE-2025-51536CriAug 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

  • CVE-2025-51535CriAug 4, 2025
    risk 0.59cvss 9.1epss 0.00

    Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.

  • CVE-2025-60915HigNov 24, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request.

  • CVE-2025-51534HigAug 4, 2025
    risk 0.53cvss 8.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.

  • CVE-2025-60916MedNov 24, 2025
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge…

  • CVE-2025-60917MedNov 24, 2025
    risk 0.30cvss 4.6epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the color…

  • CVE-2025-60914MedNov 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint.