{"schema_version":1,"title":"horizon (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in horizon (PyPI): 0 in the last 7 days and 7 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-89054, was published on 10 September 2026.","url":"https://junglewise.ai/threats/technologies/horizon","json_url":"https://junglewise.ai/threats/technologies/horizon.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/horizon","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":7,"last_365_days":9},"latest":[{"cve":"CVE-2026-89054","cvss":8.2,"epss":0.0051,"slug":"cve-2026-89054-opennms-horizon-authorization-bypass-in-api-v2-patch-endpoints","title":"OpenNMS Horizon authorization bypass in /api/v2 PATCH endpoints","severity":"high","exploited":false,"published_at":"2026-09-10T20:17:31.973+00:00","url":"https://junglewise.ai/threats/cve-2026-89054-opennms-horizon-authorization-bypass-in-api-v2-patch-endpoints"},{"cve":"CVE-2017-7400","cvss":3,"epss":0.0106,"slug":"cve-2017-7400-openstack-horizon-cross-site-scripting-xss","title":"PYSEC-2026-821 - OpenStack Horizon Cross-site Scripting (XSS)","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:24.141443+00:00","url":"https://junglewise.ai/threats/cve-2017-7400-openstack-horizon-cross-site-scripting-xss"},{"cve":"CVE-2014-0157","cvss":4,"epss":0.0122,"slug":"cve-2014-0157-openstack-dashboard-aka-horizon-vulnerable-to-cross-site-scripting","title":"PYSEC-2026-822 - OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:23.354117+00:00","url":"https://junglewise.ai/threats/cve-2014-0157-openstack-dashboard-aka-horizon-vulnerable-to-cross-site-scripting"},{"cve":"CVE-2014-3473","epss":0.017,"slug":"cve-2014-3473-horizon-orchestration-cross-site-scripting-xss-vulnerability","title":"PYSEC-2026-642 - Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.188473+00:00","url":"https://junglewise.ai/threats/cve-2014-3473-horizon-orchestration-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2014-3474","epss":0.0193,"slug":"cve-2014-3474-openstack-horizon-cross-site-scripting-xss-vulnerability","title":"PYSEC-2026-644 - OpenStack Horizon Cross-site scripting (XSS) vulnerability","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.11559+00:00","url":"https://junglewise.ai/threats/cve-2014-3474-openstack-horizon-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2014-3594","epss":0.0207,"slug":"cve-2014-3594-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability","title":"PYSEC-2026-641 - OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface","severity":"info","exploited":false,"published_at":"2026-07-02T14:13:23.057018+00:00","url":"https://junglewise.ai/threats/cve-2014-3594-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2016-4428","cvss":3.1,"epss":0.0209,"slug":"cve-2016-4428-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability","title":"PYSEC-2026-643 - OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:22.820828+00:00","url":"https://junglewise.ai/threats/cve-2016-4428-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2026-55748","cvss":6,"epss":0.0046,"slug":"cve-2026-55748-openstack-horizon-command-injection-in-openrc-file-generation","title":"OpenStack Horizon command injection in OpenRC file generation","severity":"medium","exploited":false,"published_at":"2026-06-17T15:17:02.503+00:00","url":"https://junglewise.ai/threats/cve-2026-55748-openstack-horizon-command-injection-in-openrc-file-generation"},{"cve":"CVE-2026-43002","cvss":5.3,"epss":0.006,"slug":"cve-2026-43002-openstack-horizon-denial-of-service-via-session-storage","title":"OpenStack Horizon denial of service via session storage exhaustion","severity":"medium","exploited":false,"published_at":"2026-05-05T17:17:04.92+00:00","url":"https://junglewise.ai/threats/cve-2026-43002-openstack-horizon-denial-of-service-via-session-storage"},{"cve":"CVE-2022-45582","cvss":3.1,"epss":0.008,"slug":"cve-2022-45582-horizon-web-dashboard-open-redirect-vulnerability","title":"PYSEC-2023-153 - Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.","severity":"low","exploited":false,"published_at":"2023-08-22T19:16:00+00:00","url":"https://junglewise.ai/threats/cve-2022-45582-horizon-web-dashboard-open-redirect-vulnerability"},{"cve":"CVE-2020-29565","cvss":3.1,"epss":0.0143,"slug":"cve-2020-29565-openstack-horizon-open-redirect-in-workflow-forms","title":"PYSEC-2020-45 - An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a","severity":"low","exploited":false,"published_at":"2020-12-04T08:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-29565-openstack-horizon-open-redirect-in-workflow-forms"},{"cve":"CVE-2015-3219","cvss":3.1,"epss":0.032,"slug":"cve-2015-3219-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability","title":"PYSEC-2015-40 - Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015","severity":"low","exploited":false,"published_at":"2015-08-20T20:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-3219-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2012-3540","epss":0.0292,"slug":"cve-2012-3540-pysec-2012-18-open-redirect-vulnerability-in-views-auth-forms-py","title":"PYSEC-2012-18 - Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users","severity":"info","exploited":false,"published_at":"2012-09-05T23:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-3540-pysec-2012-18-open-redirect-vulnerability-in-views-auth-forms-py"},{"cve":"CVE-2012-2094","epss":0.0244,"slug":"cve-2012-2094-openstack-horizon-cross-site-scripting-xss-vulnerability","title":"PYSEC-2012-32 - Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Das","severity":"info","exploited":false,"published_at":"2012-06-05T22:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-2094-openstack-horizon-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2012-2144","epss":0.0213,"slug":"cve-2012-2144-openstack-horizon-session-fixation","title":"PYSEC-2012-33 - Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the s","severity":"info","exploited":false,"published_at":"2012-06-05T22:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-2144-openstack-horizon-session-fixation"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"horizon (PyPI)","slug":"horizon","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/horizon/","repo_url":"https://github.com/pypa/horizon","description":"Horizon is a Python package available via the Python Package Index (PyPI).","url":"https://junglewise.ai/threats/technologies/horizon"},"most_severe":[{"cve":"CVE-2026-89054","cvss":8.2,"epss":0.0051,"slug":"cve-2026-89054-opennms-horizon-authorization-bypass-in-api-v2-patch-endpoints","title":"OpenNMS Horizon authorization bypass in /api/v2 PATCH endpoints","severity":"high","exploited":false,"published_at":"2026-09-10T20:17:31.973+00:00","url":"https://junglewise.ai/threats/cve-2026-89054-opennms-horizon-authorization-bypass-in-api-v2-patch-endpoints"},{"cve":"CVE-2026-55748","cvss":6,"epss":0.0046,"slug":"cve-2026-55748-openstack-horizon-command-injection-in-openrc-file-generation","title":"OpenStack Horizon command injection in OpenRC file generation","severity":"medium","exploited":false,"published_at":"2026-06-17T15:17:02.503+00:00","url":"https://junglewise.ai/threats/cve-2026-55748-openstack-horizon-command-injection-in-openrc-file-generation"},{"cve":"CVE-2026-43002","cvss":5.3,"epss":0.006,"slug":"cve-2026-43002-openstack-horizon-denial-of-service-via-session-storage","title":"OpenStack Horizon denial of service via session storage exhaustion","severity":"medium","exploited":false,"published_at":"2026-05-05T17:17:04.92+00:00","url":"https://junglewise.ai/threats/cve-2026-43002-openstack-horizon-denial-of-service-via-session-storage"},{"cve":"CVE-2014-0157","cvss":4,"epss":0.0122,"slug":"cve-2014-0157-openstack-dashboard-aka-horizon-vulnerable-to-cross-site-scripting","title":"PYSEC-2026-822 - OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting","severity":"medium","exploited":false,"published_at":"2026-07-06T08:03:23.354117+00:00","url":"https://junglewise.ai/threats/cve-2014-0157-openstack-dashboard-aka-horizon-vulnerable-to-cross-site-scripting"},{"cve":"CVE-2015-3219","cvss":3.1,"epss":0.032,"slug":"cve-2015-3219-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability","title":"PYSEC-2015-40 - Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015","severity":"low","exploited":false,"published_at":"2015-08-20T20:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-3219-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2016-4428","cvss":3.1,"epss":0.0209,"slug":"cve-2016-4428-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability","title":"PYSEC-2026-643 - OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:22.820828+00:00","url":"https://junglewise.ai/threats/cve-2016-4428-openstack-dashboard-horizon-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2020-29565","cvss":3.1,"epss":0.0143,"slug":"cve-2020-29565-openstack-horizon-open-redirect-in-workflow-forms","title":"PYSEC-2020-45 - An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a","severity":"low","exploited":false,"published_at":"2020-12-04T08:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-29565-openstack-horizon-open-redirect-in-workflow-forms"},{"cve":"CVE-2022-45582","cvss":3.1,"epss":0.008,"slug":"cve-2022-45582-horizon-web-dashboard-open-redirect-vulnerability","title":"PYSEC-2023-153 - Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.","severity":"low","exploited":false,"published_at":"2023-08-22T19:16:00+00:00","url":"https://junglewise.ai/threats/cve-2022-45582-horizon-web-dashboard-open-redirect-vulnerability"},{"cve":"CVE-2017-7400","cvss":3,"epss":0.0106,"slug":"cve-2017-7400-openstack-horizon-cross-site-scripting-xss","title":"PYSEC-2026-821 - OpenStack Horizon Cross-site Scripting (XSS)","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:24.141443+00:00","url":"https://junglewise.ai/threats/cve-2017-7400-openstack-horizon-cross-site-scripting-xss"},{"cve":"CVE-2012-3540","epss":0.0292,"slug":"cve-2012-3540-pysec-2012-18-open-redirect-vulnerability-in-views-auth-forms-py","title":"PYSEC-2012-18 - Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users","severity":"info","exploited":false,"published_at":"2012-09-05T23:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-3540-pysec-2012-18-open-redirect-vulnerability-in-views-auth-forms-py"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}