openclaw-dashboard vulnerabilities
CVEs whose affected-version data names the openclaw-dashboard package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-66421Critical· 9.3PoCOpenClaw Dashboard Stored XSS via lastMessage Session Field
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript me…
▾ Abyssaltugcantopaloglu · openclaw-dashboardEPSS 0.63%via CVEORG
CVE-2026-66418Critical· 9.3PoCOpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…
▾ Abyssaltugcantopaloglu · openclaw-dashboardEPSS 0.63%via NVD