PatchSiren

Open-Web-Analytics CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Open-Web-Analytics CVE published 2026-09-25

CVE-2026-97865

A security flaw has been discovered in Open-Web-Analytics up to 1.8.1, affecting the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint, allowing for deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 addresses this issue with patch 78c1222ec0e2119d84684032da1541120a2cdd23. This vulnerability has a medium severity and defenders s [truncated]