Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-48088: CWE-862: Missing Authorization in open-reception appointment-booking-softwareCVE-2026-48088
0

OpenReception appointment booking software prior to version 1.0.4 contains a missing authorization vulnerability in the route POST /api/tenants/{tenantId}/staff/{staffId}/crypto. This flaw allows unauthenticated attackers to store arbitrary encryption public keys for any tenant, effectively registering themselves as recipients of encrypted appointment data. The vulnerability breaks the platform's end-to-end encryption guarantees by enabling attackers to decrypt sensitive appointment information. A variant of the bug suppresses security warning logs, making detection harder. The issue is patched in version 1.0.4.

Join the discussion
CVE-2026-48087: CWE-287: Improper Authentication in open-reception appointment-booking-softwareCVE-2026-48087
0

CVE-2026-48087 is a critical improper authentication vulnerability in OpenReception's appointment booking software prior to version 1.0.2. The flaw allows an unauthenticated attacker to register a WebAuthn passkey credential under a victim's user ID by exploiting insufficient validation between the userId in the URL and the email associated with the registration cookie. This enables the attacker to impersonate the victim and gain unauthorized access to their account. The issue is fixed in version 1.0.2.

Join the discussion
CVE-2026-48086: CWE-269: Improper Privilege Management in open-reception appointment-booking-softwareCVE-2026-48086
0

OpenReception appointment booking software prior to version 1.0.2 contains an improper privilege management vulnerability allowing a tenant administrator to escalate their privileges to platform-wide global administrator via a single API request. This flaw permits unauthorized full control over all tenants on the platform. The issue is fixed in version 1.0.2.

Join the discussion
CVE-2026-48085: CWE-862: Missing Authorization in open-reception appointment-booking-softwareCVE-2026-48085
0

OpenReception appointment booking software prior to version 1.0.1 contains a critical missing authorization vulnerability. An unauthenticated attacker can create additional global administrator accounts via a POST request to the /setup/create-admin-account endpoint, bypassing checks that an admin already exists. These accounts are created active and immediately usable without email confirmation. The vulnerability allows full platform-level administrative control without authentication. The issue is fixed in version 1.0.1.

Join the discussion
CVE-2026-48084: CWE-307: Improper Restriction of Excessive Authentication Attempts in open-reception appointment-booking-softwareCVE-2026-48084
0

OpenReception's appointment booking software prior to version 1.0.2 does not throttle failed passphrase login attempts, allowing attackers to perform unlimited guesses against known email addresses. This lack of rate limiting on the passphrase login path enables credential stuffing and dictionary attacks, despite the presence of throttling on the WebAuthn login path. The issue is patched in version 1.0.2.

Join the discussion
CVE-2026-48083: CWE-117: Improper Output Neutralization for Logs in open-reception appointment-booking-softwareCVE-2026-48083
0

OpenReception's appointment booking software prior to version 1.0.2 has a vulnerability in its /api/log endpoint that allows unauthenticated attackers to inject arbitrary log entries. This can lead to forged log lines, denial of service via log saturation, and oversized payload submissions. The vulnerability is fixed in version 1.0.2.

Join the discussion
CVE-2026-48082: CWE-770: Allocation of Resources Without Limits or Throttling in open-reception appointment-booking-softwareCVE-2026-48082
0

OpenReception's appointment booking software prior to version 1.0.6 uses a weak proof-of-work (PoW) challenge as a rate-limiter for unauthenticated clients. The PoW difficulty is set to 16 bits, which modern hardware can solve in under 200 milliseconds, making it ineffective against automated abuse. Additionally, the server-side throttle mechanism can be bypassed by attackers supplying attacker-controlled values, allowing repeated attempts without effective rate-limiting. Version 1.0.6 addresses this issue.

Join the discussion
CVE-2026-48081: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in open-reception appointment-booking-softwareCVE-2026-48081
0

OpenReception's appointment booking software prior to version 1.0.2 contains a cross-site scripting (XSS) vulnerability. A TENANT_ADMIN can configure tenant links with javascript: URLs that are rendered without URL-scheme filtering on the patient-facing landing page. This allows execution of arbitrary JavaScript in the patient's browser, compromising patient data before client-side encryption. Version 1.0.2 addresses this issue.

Join the discussion
CVE-2026-48080: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in open-reception appointment-booking-softwareCVE-2026-48080
0

OpenReception's appointment booking software prior to version 1.0.2 exposes the full tenant record, including the PostgreSQL connection string with superuser credentials, to any authenticated TENANT_ADMIN of that tenant. This exposure allows a TENANT_ADMIN to access and manipulate all tenant databases and the central database, breaking tenant isolation. Version 1.0.2 addresses this issue.

Join the discussion
CVE-2026-48079: CWE-613: Insufficient Session Expiration in open-reception appointment-booking-softwareCVE-2026-48079
0

CVE-2026-48079 is a high-severity vulnerability in OpenReception's appointment booking software prior to version 1.0.2. The issue involves insufficient session expiration during logout due to a server-side logic error. When users log out via the `/logout` page, the session revocation does not occur properly, allowing sessions to remain valid until their natural expiry, even though the user interface indicates a successful logout. This enables continued authenticated API access by anyone holding a copy of the deleted access token. The flaw is fixed starting with version 1.0.2, which corrects the logout sequence, and later versions implement a race-free client-side logout flow.

Join the discussion

Showing 1 to 10 of 16 results

Filters:Package: pkg:github/open-reception/appointment-booking-software
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses