VulnSea

openzeppelin has 4 CVEs on record. 3 were published in the last 90 days. The median CVSS is 3.3 (low). The most common weakness class is CWE-94 (3). Most affected products: contracts-wizard (2), @openzeppelin/confidential-contracts (1), @openzeppelin/wizard (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
3.3
Publish → KEV
—
Last 90 days
3 prev 1

Products

  • contracts-wizard 2
  • @openzeppelin/confidential-contracts 1
  • @openzeppelin/wizard 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

openzeppelin vulnerabilities

CVEs affecting openzeppelin, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

GHSA-29h2-jr22-frmhHigh
2d ago

OpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract private data from the vesting wallet

OpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract private data from the vesting wallet

▾ Twilightopenzeppelin · @openzeppelin/confidential-contractsvia GHSA
CVE-2026-57583Low· 3.3
1w ago

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6…

▾ SunlitOpenZeppelin · contracts-wizardEPSS 0.19%via NVD
CVE-2026-48054High· 8.8
1mo ago

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `op…

▾ TwilightOpenZeppelin · contracts-wizardEPSS 0.64%via NVD
GHSA-9wxg-vf3r-56hcLow· 3.3
3mo ago

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

▾ Sunlitopenzeppelin · @openzeppelin/wizardvia GHSA
openzeppelin vulnerabilities (CVEs) · VulnSea