Openstack Horizon vulnerabilities
23 known vulnerabilities affecting openstack/horizon.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM18LOW5
Vulnerabilities
Page 2 of 2
CVE-2014-8578P4LOWCVSS 3.5≥ 2013.2, < 2013.2.4≥ 2014.1, < 2014.1.2+2 more2014-10-31
CVE-2014-8578 [LOW] CVE-2014-8578: Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475.
nvdosv
CVE-2014-3475P4LOWCVSS 3.5≥ 2013.2, < 2013.2.4≥ 2014.1, < 2014.1.2+1 more2014-10-31
CVE-2014-3475 [LOW] CWE-79 CVE-2014-3475: Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (H
Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-8578.
nvdosv
CVE-2026-55748MEDIUMCVSS 6.0≥ 8.0.0, < 25.3.3≥ 25.4.0, < 25.5.3+1 more2026-06-17
CVE-2026-55748 [MEDIUM] CWE-78 CVE-2026-55748: OpenStack Horizon before 25
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
cvelistv5
← Previous2 / 2