OpenSlides
Products
1- 8 CVEs
Recent CVEs
8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-22893 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2024 | OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack. | ||
| CVE-2024-22892 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2024 | OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords. | ||
| CVE-2025-30342 | Med | 0.35 | 5.4 | 0.00 | Mar 21, 2025 | An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element,… | ||
| CVE-2025-30344 | Med | 0.34 | 5.3 | 0.00 | Mar 21, 2025 | An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100… | ||
| CVE-2025-30345 | Low | 0.23 | 3.5 | 0.00 | Mar 21, 2025 | An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded… | ||
| CVE-2025-30343 | Low | 0.20 | 3.0 | 0.00 | Mar 21, 2025 | A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the… | ||
| CVE-2026-25519 | Hig | 0.00 | 8.1 | 0.00 | Feb 4, 2026 | OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to version 4.2.29, OpenSlides supports local logins with username and password or an optionally configurable single sign on with SAML… | ||
| CVE-2020-26280 | Hig | 0.00 | 8.9 | 0.01 | Dec 18, 2020 | OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and elections of assemblies. OpenSlides version 3.2, due to unsufficient user input validation and escaping, it is vulnerable to persistant cross-site scripting (XSS).… |
- risk 0.49cvss 7.5epss 0.00
OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.
- risk 0.49cvss 7.5epss 0.00
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
- risk 0.35cvss 5.4epss 0.00
An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element,…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100…
- risk 0.23cvss 3.5epss 0.00
An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded…
- risk 0.20cvss 3.0epss 0.00
A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the…
- risk 0.00cvss 8.1epss 0.00
OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to version 4.2.29, OpenSlides supports local logins with username and password or an optionally configurable single sign on with SAML…
- risk 0.00cvss 8.9epss 0.01
OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and elections of assemblies. OpenSlides version 3.2, due to unsufficient user input validation and escaping, it is vulnerable to persistant cross-site scripting (XSS).…