{"schema_version":1,"title":"OpenPanel vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in OpenPanel: 1 in the last 7 days and 14 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93983, was published on 19 September 2026.","url":"https://junglewise.ai/threats/technologies/openpanel","json_url":"https://junglewise.ai/threats/technologies/openpanel.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openpanel","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":14,"critical":0,"exploited":0,"last_7_days":1,"last_30_days":12,"last_90_days":14,"last_365_days":14},"latest":[{"cve":"CVE-2026-93983","cvss":5,"epss":0.0033,"slug":"cve-2026-93983-openpanel-through-commit-bad75bdd-fails-to-escape-property-keys","title":"OpenPanel SQL injection in ClickHouse property key filtering","severity":"medium","exploited":false,"published_at":"2026-09-19T12:16:41.493+00:00","url":"https://junglewise.ai/threats/cve-2026-93983-openpanel-through-commit-bad75bdd-fails-to-escape-property-keys"},{"cve":"CVE-2026-88893","cvss":7.5,"epss":0.0043,"slug":"cve-2026-88893-openpanel-unauthenticated-share-lookup-information-disclosure","title":"OpenPanel unauthenticated share lookup information disclosure","severity":"high","exploited":false,"published_at":"2026-09-10T14:17:18.62+00:00","url":"https://junglewise.ai/threats/cve-2026-88893-openpanel-unauthenticated-share-lookup-information-disclosure"},{"cve":"CVE-2026-88892","cvss":5,"epss":0.0028,"slug":"cve-2026-88892-openpanel-ssrf-in-data-importer-via-unguarded-fetch","title":"OpenPanel SSRF in data importer via unguarded fetch","severity":"medium","exploited":false,"published_at":"2026-09-10T14:17:18.48+00:00","url":"https://junglewise.ai/threats/cve-2026-88892-openpanel-ssrf-in-data-importer-via-unguarded-fetch"},{"cve":"CVE-2026-88891","cvss":8.3,"epss":0.0037,"slug":"cve-2026-88891-openpanel-privilege-escalation-in-mutation-resolvers-via-missing","title":"OpenPanel privilege escalation in mutation resolvers via missing access level validation","severity":"high","exploited":false,"published_at":"2026-09-10T14:17:18.34+00:00","url":"https://junglewise.ai/threats/cve-2026-88891-openpanel-privilege-escalation-in-mutation-resolvers-via-missing"},{"cve":"CVE-2026-88890","cvss":8.5,"epss":0.0039,"slug":"cve-2026-88890-openpanel-sql-injection-in-analytics-filter-builder","title":"OpenPanel SQL injection in analytics filter builder","severity":"high","exploited":false,"published_at":"2026-09-10T14:17:18.2+00:00","url":"https://junglewise.ai/threats/cve-2026-88890-openpanel-sql-injection-in-analytics-filter-builder"},{"cve":"CVE-2026-85615","cvss":6.4,"epss":0.0024,"slug":"cve-2026-85615-openpanel-cross-tenant-idor-in-report-layout-handlers","title":"Openpanel cross-tenant IDOR in report layout handlers","severity":"medium","exploited":false,"published_at":"2026-09-04T12:17:25.13+00:00","url":"https://junglewise.ai/threats/cve-2026-85615-openpanel-cross-tenant-idor-in-report-layout-handlers"},{"cve":"CVE-2026-85614","cvss":8.6,"epss":0.0026,"slug":"cve-2026-85614-openpanel-unauthenticated-ssrf-in-site-checker","title":"OpenPanel unauthenticated SSRF in site-checker","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.993+00:00","url":"https://junglewise.ai/threats/cve-2026-85614-openpanel-unauthenticated-ssrf-in-site-checker"},{"cve":"CVE-2026-85613","cvss":8.2,"epss":0.004,"slug":"cve-2026-85613-openpanel-unauthenticated-xss-in-svg-favicon-proxy","title":"OpenPanel unauthenticated XSS in SVG favicon proxy","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.863+00:00","url":"https://junglewise.ai/threats/cve-2026-85613-openpanel-unauthenticated-xss-in-svg-favicon-proxy"},{"cve":"CVE-2026-85612","cvss":7.5,"epss":0.0041,"slug":"cve-2026-85612-openpanel-server-side-request-forgery-in-favicon-and-og-endpoints","title":"OpenPanel server-side request forgery in favicon and OG endpoints","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.727+00:00","url":"https://junglewise.ai/threats/cve-2026-85612-openpanel-server-side-request-forgery-in-favicon-and-og-endpoints"},{"cve":"CVE-2026-85611","cvss":6.4,"epss":0.0024,"slug":"cve-2026-85611-openpanel-cross-tenant-broken-object-level-authorization-in","title":"OpenPanel cross-tenant broken object level authorization in report procedures","severity":"medium","exploited":false,"published_at":"2026-09-04T12:17:24.593+00:00","url":"https://junglewise.ai/threats/cve-2026-85611-openpanel-cross-tenant-broken-object-level-authorization-in"},{"cve":"CVE-2026-85610","cvss":8.8,"epss":0.0071,"slug":"cve-2026-85610-openpanel-chart-formula-code-injection-via-mathjs","title":"OpenPanel chart formula code injection via mathjs","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.463+00:00","url":"https://junglewise.ai/threats/cve-2026-85610-openpanel-chart-formula-code-injection-via-mathjs"},{"cve":"CVE-2026-85609","cvss":7.5,"epss":0.005,"slug":"cve-2026-85609-openpanel-site-checker-unauthenticated-ssrf","title":"Openpanel site-checker unauthenticated SSRF","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.317+00:00","url":"https://junglewise.ai/threats/cve-2026-85609-openpanel-site-checker-unauthenticated-ssrf"},{"cve":"CVE-2026-77769","cvss":6.5,"epss":0.0031,"slug":"cve-2026-77769-openpanel-authorization-bypass-in-report-listing","title":"OpenPanel authorization bypass in report listing","severity":"medium","exploited":false,"published_at":"2026-08-21T11:17:07.43+00:00","url":"https://junglewise.ai/threats/cve-2026-77769-openpanel-authorization-bypass-in-report-listing"},{"cve":"CVE-2026-77768","cvss":6.5,"epss":0.0031,"slug":"cve-2026-77768-openpanel-report-get-authorization-bypass","title":"OpenPanel report.get authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-21T11:17:07.283+00:00","url":"https://junglewise.ai/threats/cve-2026-77768-openpanel-report-get-authorization-bypass"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"OpenPanel","slug":"openpanel","vendor":{"name":"OpenPanel","slug":"openpanel","url":"https://junglewise.ai/threats/vendors/openpanel"},"aliases":[],"category":"web-analytics","url":"https://junglewise.ai/threats/technologies/openpanel"},"most_severe":[{"cve":"CVE-2026-85610","cvss":8.8,"epss":0.0071,"slug":"cve-2026-85610-openpanel-chart-formula-code-injection-via-mathjs","title":"OpenPanel chart formula code injection via mathjs","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.463+00:00","url":"https://junglewise.ai/threats/cve-2026-85610-openpanel-chart-formula-code-injection-via-mathjs"},{"cve":"CVE-2026-85614","cvss":8.6,"epss":0.0026,"slug":"cve-2026-85614-openpanel-unauthenticated-ssrf-in-site-checker","title":"OpenPanel unauthenticated SSRF in site-checker","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.993+00:00","url":"https://junglewise.ai/threats/cve-2026-85614-openpanel-unauthenticated-ssrf-in-site-checker"},{"cve":"CVE-2026-88890","cvss":8.5,"epss":0.0039,"slug":"cve-2026-88890-openpanel-sql-injection-in-analytics-filter-builder","title":"OpenPanel SQL injection in analytics filter builder","severity":"high","exploited":false,"published_at":"2026-09-10T14:17:18.2+00:00","url":"https://junglewise.ai/threats/cve-2026-88890-openpanel-sql-injection-in-analytics-filter-builder"},{"cve":"CVE-2026-88891","cvss":8.3,"epss":0.0037,"slug":"cve-2026-88891-openpanel-privilege-escalation-in-mutation-resolvers-via-missing","title":"OpenPanel privilege escalation in mutation resolvers via missing access level validation","severity":"high","exploited":false,"published_at":"2026-09-10T14:17:18.34+00:00","url":"https://junglewise.ai/threats/cve-2026-88891-openpanel-privilege-escalation-in-mutation-resolvers-via-missing"},{"cve":"CVE-2026-85613","cvss":8.2,"epss":0.004,"slug":"cve-2026-85613-openpanel-unauthenticated-xss-in-svg-favicon-proxy","title":"OpenPanel unauthenticated XSS in SVG favicon proxy","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.863+00:00","url":"https://junglewise.ai/threats/cve-2026-85613-openpanel-unauthenticated-xss-in-svg-favicon-proxy"},{"cve":"CVE-2026-85609","cvss":7.5,"epss":0.005,"slug":"cve-2026-85609-openpanel-site-checker-unauthenticated-ssrf","title":"Openpanel site-checker unauthenticated SSRF","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.317+00:00","url":"https://junglewise.ai/threats/cve-2026-85609-openpanel-site-checker-unauthenticated-ssrf"},{"cve":"CVE-2026-88893","cvss":7.5,"epss":0.0043,"slug":"cve-2026-88893-openpanel-unauthenticated-share-lookup-information-disclosure","title":"OpenPanel unauthenticated share lookup information disclosure","severity":"high","exploited":false,"published_at":"2026-09-10T14:17:18.62+00:00","url":"https://junglewise.ai/threats/cve-2026-88893-openpanel-unauthenticated-share-lookup-information-disclosure"},{"cve":"CVE-2026-85612","cvss":7.5,"epss":0.0041,"slug":"cve-2026-85612-openpanel-server-side-request-forgery-in-favicon-and-og-endpoints","title":"OpenPanel server-side request forgery in favicon and OG endpoints","severity":"high","exploited":false,"published_at":"2026-09-04T12:17:24.727+00:00","url":"https://junglewise.ai/threats/cve-2026-85612-openpanel-server-side-request-forgery-in-favicon-and-og-endpoints"},{"cve":"CVE-2026-77769","cvss":6.5,"epss":0.0031,"slug":"cve-2026-77769-openpanel-authorization-bypass-in-report-listing","title":"OpenPanel authorization bypass in report listing","severity":"medium","exploited":false,"published_at":"2026-08-21T11:17:07.43+00:00","url":"https://junglewise.ai/threats/cve-2026-77769-openpanel-authorization-bypass-in-report-listing"},{"cve":"CVE-2026-77768","cvss":6.5,"epss":0.0031,"slug":"cve-2026-77768-openpanel-report-get-authorization-bypass","title":"OpenPanel report.get authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-21T11:17:07.283+00:00","url":"https://junglewise.ai/threats/cve-2026-77768-openpanel-report-get-authorization-bypass"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}