{"schema_version":1,"title":"OpenReception vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in OpenReception: 0 in the last 7 days and 16 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54460, was published on 17 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/openreception","json_url":"https://junglewise.ai/threats/vendors/openreception.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/openreception","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":16,"critical":5,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":16,"last_365_days":16},"latest":[{"cve":"CVE-2026-54460","cvss":9.8,"epss":0.007,"slug":"cve-2026-54460-openreception-appointment-booking-software-authentication-bypass","title":"OpenReception Appointment Booking Software authentication bypass in passkey enrollment","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:15.557+00:00","url":"https://junglewise.ai/threats/cve-2026-54460-openreception-appointment-booking-software-authentication-bypass"},{"cve":"CVE-2026-48088","cvss":9.4,"epss":0.0038,"slug":"cve-2026-48088-openreception-authentication-bypass-in-appointment-crypto-key","title":"OpenReception authentication bypass in appointment crypto key storage","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.893+00:00","url":"https://junglewise.ai/threats/cve-2026-48088-openreception-authentication-bypass-in-appointment-crypto-key"},{"cve":"CVE-2026-48087","cvss":9.8,"epss":0.0057,"slug":"cve-2026-48087-openreception-appointment-booking-webauthn-passkey-injection","title":"OpenReception appointment booking WebAuthn passkey injection","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.75+00:00","url":"https://junglewise.ai/threats/cve-2026-48087-openreception-appointment-booking-webauthn-passkey-injection"},{"cve":"CVE-2026-48086","cvss":9.9,"epss":0.0044,"slug":"cve-2026-48086-openreception-privilege-escalation-in-role-update-handler","title":"OpenReception privilege escalation in role-update handler","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.593+00:00","url":"https://junglewise.ai/threats/cve-2026-48086-openreception-privilege-escalation-in-role-update-handler"},{"cve":"CVE-2026-48085","cvss":9.8,"epss":0.0059,"slug":"cve-2026-48085-openreception-authentication-bypass-in-admin-account-creation","title":"OpenReception authentication bypass in admin account creation","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.44+00:00","url":"https://junglewise.ai/threats/cve-2026-48085-openreception-authentication-bypass-in-admin-account-creation"},{"cve":"CVE-2026-48083","cvss":6.5,"epss":0.0036,"slug":"cve-2026-48083-openreception-appointment-booking-software-log-injection-with","title":"OpenReception appointment-booking-software log injection with CRLF injection and DoS","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:11.143+00:00","url":"https://junglewise.ai/threats/cve-2026-48083-openreception-appointment-booking-software-log-injection-with"},{"cve":"CVE-2026-48082","cvss":3.7,"epss":0.0039,"slug":"cve-2026-48082-openreception-appointment-booking-software-weak-proof-of-work-in","title":"OpenReception appointment booking software weak proof-of-work in bootstrap challenge","severity":"low","exploited":false,"published_at":"2026-08-06T22:17:10.997+00:00","url":"https://junglewise.ai/threats/cve-2026-48082-openreception-appointment-booking-software-weak-proof-of-work-in"},{"cve":"CVE-2026-48081","cvss":8.1,"epss":0.0024,"slug":"cve-2026-48081-openreception-stored-xss-via-javascript-tenant-links","title":"OpenReception stored XSS via javascript: tenant links","severity":"high","exploited":false,"published_at":"2026-08-06T22:17:10.85+00:00","url":"https://junglewise.ai/threats/cve-2026-48081-openreception-stored-xss-via-javascript-tenant-links"},{"cve":"CVE-2026-48080","cvss":8,"epss":0.0047,"slug":"cve-2026-48080-openreception-appointment-booking-software-database-credential","title":"OpenReception appointment booking software database credential disclosure","severity":"high","exploited":false,"published_at":"2026-08-06T22:17:10.703+00:00","url":"https://junglewise.ai/threats/cve-2026-48080-openreception-appointment-booking-software-database-credential"},{"cve":"CVE-2026-48079","cvss":7.4,"epss":0.005,"slug":"cve-2026-48079-openreception-appointment-booking-software-session-fixation-via","title":"OpenReception appointment booking software session fixation via logout race condition","severity":"high","exploited":false,"published_at":"2026-08-06T22:17:10.557+00:00","url":"https://junglewise.ai/threats/cve-2026-48079-openreception-appointment-booking-software-session-fixation-via"},{"cve":"CVE-2026-48078","cvss":5.3,"epss":0.0034,"slug":"cve-2026-48078-openreception-appointment-booking-software-information-disclosure","title":"OpenReception appointment booking software information disclosure in schedule endpoint","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:10.42+00:00","url":"https://junglewise.ai/threats/cve-2026-48078-openreception-appointment-booking-software-information-disclosure"},{"cve":"CVE-2026-48077","cvss":5.3,"epss":0.0043,"slug":"cve-2026-48077-openreception-appointment-booking-missing-authorization-in-get","title":"OpenReception appointment booking missing authorization in GET handler","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:10.267+00:00","url":"https://junglewise.ai/threats/cve-2026-48077-openreception-appointment-booking-missing-authorization-in-get"},{"cve":"CVE-2026-48076","cvss":6.5,"epss":0.0033,"slug":"cve-2026-48076-openreception-appointment-booking-unauthorized-channel-access","title":"OpenReception appointment booking unauthorized channel access","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:10.127+00:00","url":"https://junglewise.ai/threats/cve-2026-48076-openreception-appointment-booking-unauthorized-channel-access"},{"cve":"CVE-2026-48075","cvss":6.5,"epss":0.0042,"slug":"cve-2026-48075-openreception-appointment-booking-auth-bypass-in-add-to-tunnel","title":"OpenReception appointment booking auth bypass in add-to-tunnel endpoint","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:09.977+00:00","url":"https://junglewise.ai/threats/cve-2026-48075-openreception-appointment-booking-auth-bypass-in-add-to-tunnel"},{"cve":"CVE-2026-48074","cvss":2.7,"epss":0.0029,"slug":"cve-2026-48074-openreception-appointment-booking-software-cross-tenant-invite","title":"OpenReception appointment booking software cross-tenant invite deletion","severity":"low","exploited":false,"published_at":"2026-08-06T22:17:09.833+00:00","url":"https://junglewise.ai/threats/cve-2026-48074-openreception-appointment-booking-software-cross-tenant-invite"},{"cve":"CVE-2026-48071","cvss":5.8,"epss":0.004,"slug":"cve-2026-48071-openreception-appointment-booking-cross-tenant-rate-limit-bypass","title":"OpenReception appointment booking cross-tenant rate limit bypass","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:09.68+00:00","url":"https://junglewise.ai/threats/cve-2026-48071-openreception-appointment-booking-cross-tenant-rate-limit-bypass"}],"vendor":{"hub":true,"name":"OpenReception","slug":"openreception","url":"https://junglewise.ai/threats/vendors/openreception"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":4,"exploited":0,"vulnerabilities":15},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-48086","cvss":9.9,"epss":0.0044,"slug":"cve-2026-48086-openreception-privilege-escalation-in-role-update-handler","title":"OpenReception privilege escalation in role-update handler","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.593+00:00","url":"https://junglewise.ai/threats/cve-2026-48086-openreception-privilege-escalation-in-role-update-handler"},{"cve":"CVE-2026-54460","cvss":9.8,"epss":0.007,"slug":"cve-2026-54460-openreception-appointment-booking-software-authentication-bypass","title":"OpenReception Appointment Booking Software authentication bypass in passkey enrollment","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:15.557+00:00","url":"https://junglewise.ai/threats/cve-2026-54460-openreception-appointment-booking-software-authentication-bypass"},{"cve":"CVE-2026-48085","cvss":9.8,"epss":0.0059,"slug":"cve-2026-48085-openreception-authentication-bypass-in-admin-account-creation","title":"OpenReception authentication bypass in admin account creation","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.44+00:00","url":"https://junglewise.ai/threats/cve-2026-48085-openreception-authentication-bypass-in-admin-account-creation"},{"cve":"CVE-2026-48087","cvss":9.8,"epss":0.0057,"slug":"cve-2026-48087-openreception-appointment-booking-webauthn-passkey-injection","title":"OpenReception appointment booking WebAuthn passkey injection","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.75+00:00","url":"https://junglewise.ai/threats/cve-2026-48087-openreception-appointment-booking-webauthn-passkey-injection"},{"cve":"CVE-2026-48088","cvss":9.4,"epss":0.0038,"slug":"cve-2026-48088-openreception-authentication-bypass-in-appointment-crypto-key","title":"OpenReception authentication bypass in appointment crypto key storage","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.893+00:00","url":"https://junglewise.ai/threats/cve-2026-48088-openreception-authentication-bypass-in-appointment-crypto-key"},{"cve":"CVE-2026-48081","cvss":8.1,"epss":0.0024,"slug":"cve-2026-48081-openreception-stored-xss-via-javascript-tenant-links","title":"OpenReception stored XSS via javascript: tenant links","severity":"high","exploited":false,"published_at":"2026-08-06T22:17:10.85+00:00","url":"https://junglewise.ai/threats/cve-2026-48081-openreception-stored-xss-via-javascript-tenant-links"},{"cve":"CVE-2026-48080","cvss":8,"epss":0.0047,"slug":"cve-2026-48080-openreception-appointment-booking-software-database-credential","title":"OpenReception appointment booking software database credential disclosure","severity":"high","exploited":false,"published_at":"2026-08-06T22:17:10.703+00:00","url":"https://junglewise.ai/threats/cve-2026-48080-openreception-appointment-booking-software-database-credential"},{"cve":"CVE-2026-48079","cvss":7.4,"epss":0.005,"slug":"cve-2026-48079-openreception-appointment-booking-software-session-fixation-via","title":"OpenReception appointment booking software session fixation via logout race condition","severity":"high","exploited":false,"published_at":"2026-08-06T22:17:10.557+00:00","url":"https://junglewise.ai/threats/cve-2026-48079-openreception-appointment-booking-software-session-fixation-via"},{"cve":"CVE-2026-48075","cvss":6.5,"epss":0.0042,"slug":"cve-2026-48075-openreception-appointment-booking-auth-bypass-in-add-to-tunnel","title":"OpenReception appointment booking auth bypass in add-to-tunnel endpoint","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:09.977+00:00","url":"https://junglewise.ai/threats/cve-2026-48075-openreception-appointment-booking-auth-bypass-in-add-to-tunnel"},{"cve":"CVE-2026-48083","cvss":6.5,"epss":0.0036,"slug":"cve-2026-48083-openreception-appointment-booking-software-log-injection-with","title":"OpenReception appointment-booking-software log injection with CRLF injection and DoS","severity":"medium","exploited":false,"published_at":"2026-08-06T22:17:11.143+00:00","url":"https://junglewise.ai/threats/cve-2026-48083-openreception-appointment-booking-software-log-injection-with"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"OpenReception Appointment-Booking-Software","slug":"appointment-booking-software","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/appointment-booking-software"}]}