CVE-2026-38751: Devcode Openstamanager
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
Affected products
- Devcode Openstamanager: up to and including 2.10
Published 2026-05-04. Last modified 2026-06-17.