PatchSiren

opencats CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenCATS CVE published 2026-05-31

CVE-2026-49490

OpenCATS versions from 0.9.1a contain an authenticated SQL injection vulnerability in DataGrid filter handling. The flaw exists in the Candidates DataGrid where the non-filterable Tags column can be targeted through crafted filter requests, allowing attackers to bypass column filterable restrictions and execute arbitrary SQL queries against the database. The vulnerability requires authentication but can l [truncated]

HIGH OpenCATS CVE published 2026-05-31

CVE-2026-49489

OpenCATS through version 0.9.7.4 contains a SQL injection vulnerability in the DataGrid component's sortDirection parameter. The flaw exists in ajax/getDataGridPager.php, where authenticated attackers can inject malicious SQL to conduct time-based blind injection attacks and extract database contents. The vulnerability requires authentication but can be exploited remotely with low attack complexity.

CRITICAL opencats CVE published 2026-04-28

CVE-2026-27760

A critical vulnerability was discovered in OpenCATS, a popular open-source candidate management system. CVE-2026-27760 is a PHP code injection vulnerability that exists in the installer AJAX endpoint. This vulnerability allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious statements into the databaseConnectivity action parameter. The vulnerability arises from the lack of p [truncated]