Vulnerabilities
12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66418 +1 in the same advisory: …66421 | Unauthenticated Stored XSS in OpenClaw Dashboard 3.0.0 Enables Admin Takeover OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability (CWE-79) that lets an unauthenticated remote attacker inject arbitrary HTML and script through the username field of a failed login POST request. The injected value is stored verbatim in the audit log and later rendered unescaped via innerHTML in the administrator's notification panel, where a permissive Content-Security-Policy permits inline event handlers, so the payload executes when an administrator opens the panel. Because the script runs in the administrator's session, the attacker can invoke authenticated endpoints — including editing agent instruction files and changing configuration — and, per the public proof-of-concept, achieve administrator account takeover. Anyone running OpenClaw Dashboard v3.0.0 whose login and notification panel are reachable to unauthenticated users is affected. The flaw is not yet in CISA's KEV and EPSS assigns roughly a 0.5% probability of exploitation within 30 days (42nd percentile), but two public proof-of-concept references are available, so opportunistic exploitation is plausible. Do: Upgrade from v3.0.0 to a patched release as soon as the vendor publishes one (no fixed version is named in the disclosure); in the meantime, restrict the dashboard login page and notification panel to trusted networks or IP allowlists. Review stored audit-log entries for injected HTML/script content, and check whether agent instruction files or configuration were modified through any admin sessions. Defensively, ensure log fields are HTML-escaped before rendering and tighten the CSP to disallow inline event handlers. | 9.3 group max | <1% | PoC ×2 |
| nichelikely hundreds to low thousands of self-hosted dashboard instances (deployment-pattern estimate; no measured install or exposure counts) | |
| CVE-2026-40317 +1 in the same advisory: …40572 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers without validation, allowing any Ring 3 user-mode process to jump to kernel addresses and execute arbitrary code in Ring 0 context, resulting in local privilege escalation. This issue has been fixed in version 0.24. If developers are unable to immediately update, they should restrict syscall access by running the system in single-user mode without Ring 3, and disable user-mode processes by only running kernel shell with no user processes. This issue has been fixed in version 0.24. NVD description · AI analysis pending | 9.3 group max | <1% | PoC |
| — | |
| CVE-2024-4936 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. This required allow_url_include to be enabled on the target site in order to exploit. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2024-25096 | Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-3452 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server. NVD description · AI analysis pending | 9.8 | 7% |
| — | ||
| CVE-2022-40305 | A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2020-28976 | The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF. NVD description · AI analysis pending | 5.3 | 28% |
| — | ||
| CVE-2020-24063 | The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. NVD description · AI analysis pending | 7.2 | 1% |
| — |