devcode-it/openstamanager Security Analysis
devcode-it/openstamanager has 14 known security vulnerabilities in Packagist (PHP). Upgrade to version 2.10.2 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 2.10.2
Upgrading to 2.10.2 or later resolves all 14 known vulnerabilities in devcode-it/openstamanager. Run: composer require devcode-it/openstamanager:^2.10.2
Is devcode-it/openstamanager in your project?
Check if you're affected and upgrade to 2.10.2 to stay secure.
Vulnerabilities
14 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2025-69212 OpenSTAManager has an OS Command Injection in P7M File Processing | CRITICAL | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2026-27012 OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.php | CRITICAL | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2026-35470 OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals | HIGH | 2.3.0, v2.10-beta, v2.10.1, v2.4 (+85 more) | 2.10.2 |
| CVE-2026-35168 OpenSTAManager: SQL Injection via Aggiornamenti Module | HIGH | 2.3.0, v2.10-beta, v2.10.1, v2.4 (+85 more) | 2.10.2 |
| CVE-2026-28805 OpenSTAManager has a Time-Based Blind SQL Injection via `options[stato]` Parameter | HIGH | 2.3.0, v2.10-beta, v2.10.1, v2.4 (+85 more) | 2.10.2 |
| CVE-2026-24419 OpenSTAManager has a SQL Injection in the Prima Nota module | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2026-24418 OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2026-24417 OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service | HIGH | 2.3.0, v2.10-beta, v2.4, v2.4.1 (+84 more) | No fix available |
| CVE-2026-24416 OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2025-69216 OpenSTAManager has a SQL Injection in Scadenzario Print Template | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2025-69214 OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint) | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2025-69215 OpenSTAManager has an SQL Injection in the Stampe Module | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2025-69213 OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint) | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+83 more) | No fix available |
| CVE-2025-65103 OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter | HIGH | 2.3.0, v2.4, v2.4.1, v2.4.10 (+79 more) | 2.9.5 |
About This Data
Vulnerability data for devcode-it/openstamanager is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Packagist (PHP) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of devcode-it/openstamanager.