openengine CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

openengine vulnerability overview

Aggregates CVE and security vulnerability intelligence across all openengine-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk input validation and vendor risk path handling and related problems; some flaws may lead to vendor impact unexpected behavior, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-4719 PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter, a different vector than CVE-2008-4329. [email protected] 9.3 2.52% 2008-10-23 2026-04-23
CVE-2008-4329 PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter. [email protected] 10.0 3.78% 2008-09-30 2026-04-23
CVE-2007-5035 PHP remote file inclusion vulnerability in html/modules/extranet_profile/main.php in openEngine 1.9 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the this_module_path parameter. NOTE: this issue is disputed by CVE because PHP encounters a fatal function-call error on a direct request for the file, before reaching the include statement [email protected] 7.5 1.02% 2007-09-24 2026-04-23
CVE-2006-2280 Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template parameter. [email protected] 5.0 4.66% 2006-05-10 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence