VulnSea

horizon vulnerabilities

CVEs whose affected-version data names the horizon package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-89089Medium· 6.5
1w ago

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "…

SunlitThe OpenNMS Group · MeridianEPSS 0.21%via NVD
CVE-2026-19596Medium· 5.9
1w ago

An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon

An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a source whose response is attacker-controlled (for example a compromised monitor…

SunlitThe OpenNMS Group · MeridianEPSS 0.21%via NVD
CVE-2026-89054High· 8.2
1w ago

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the ship…

TwilightThe OpenNMS Group · HorizonEPSS 0.35%via NVD
CVE-2026-55748Medium· 6.0
3mo ago

OpenStack Horizon RC file generation does not escape special characters in project names

OpenStack Horizon RC file generation does not escape special characters in project names

Sunlithorizon · horizonEPSS 0.22%via OSV
CVE-2026-43002Medium· 5.3
4mo ago

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression…

Sunlitopenstack · horizonEPSS 0.36%via NVD
CVE-2014-0157Medium
4y ago

OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting

OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting

Sunlithorizon · horizonEPSS 1.2%via OSV
CVE-2017-7400Medium· 4.8
4y ago

OpenStack Horizon Cross-site Scripting (XSS)

OpenStack Horizon Cross-site Scripting (XSS)

Sunlithorizon · horizonEPSS 1.3%via OSV
CVE-2014-3474Low
4y ago

OpenStack Horizon Cross-site scripting (XSS) vulnerability

OpenStack Horizon Cross-site scripting (XSS) vulnerability

Sunlithorizon · horizonEPSS 1.9%via OSV
CVE-2016-4428Medium· 5.4
4y ago

OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability

OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability

Sunlithorizon · horizonEPSS 2.1%via OSV
CVE-2014-3473Medium
4y ago

Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name

Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name

Sunlithorizon · horizonEPSS 1.7%via OSV
CVE-2014-3594Low
4y ago

OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface

OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface

Sunlithorizon · horizonEPSS 2.1%via OSV
horizon vulnerabilities (CVEs) · VulnSea