tugcantopaloglu has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.3 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- openclaw-dashboard 2
Worst active — by depth score
CVE-2026-66421Critical· 9.3OpenClaw Dashboard Stored XSS via lastMessage Session Field63CVE-2026-66418Critical· 9.3OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…63
tugcantopaloglu vulnerabilities
CVEs affecting tugcantopaloglu, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-66421Critical· 9.3PoCOpenClaw Dashboard Stored XSS via lastMessage Session Field
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript me…
CVE-2026-66418Critical· 9.3PoCOpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…