All 13 CVE vulnerabilities found in OpenPLC_V3, with AI-generated Chinese analysis, references, and POCs.
This page catalogs Common Weakness Enumeration (CWE) vulnerabilities associated with the OpenPLC_v3 product developed by thiagoralves. It aggregates security issues linked to this specific open-source software, focusing on flaws within the programmable logic controller environment that may impact operational integrity or data confidentiality. The collection includes publicly disclosed weaknesses, ranging from memory management errors to authentication bypasses, covering security advisories reported from 2020 through the present. This timeframe ensures a comprehensive view of the evolving threat landscape affecting the platform as it has gained traction in industrial automation and educational settings. Readers can use this resource to track vendor advisories and monitor the remediation status of reported defects over time. The aggregated data helps users understand the prevalence and characteristics of specific weakness classes within the context of open-source industrial control systems. Furthermore, it provides a historical perspective on the product's vulnerability profile, allowing stakeholders to assess risk exposure based on past incidents and patch deployment patterns. By centralizing this information, the page serves as a reference for security analysts, system integrators, and developers seeking to evaluate the security posture of OpenPLC_v3. Understanding these historical data points is crucial for implementing effective mitigation strategies and maintaining robust security controls in environments reliant on this software. The content is structured to facilitate easy navigation and analysis of the relationship between identified weaknesses and their respective resolutions.
Vendor: OpenPLC
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-11826 | OpenPLC_v3 Heap-Based Buffer Overflow in Modbus Master getData() CWE-122 | 8.8 | High | 2026-07-18 |
| CVE-2026-35063 | Missing Authorization in OpenPLC_V3 CWE-862 | 8.8AI | HighAI | 2026-04-09 |
| CVE-2026-35556 | Plaintext storage of a password in OpenPLC_V3 CWE-256 | 9.8AI | CriticalAI | 2026-04-09 |
| CVE-2026-28205 | Initialization of a resource with an insecure default in OpenPLC_V3 CWE-1188 | 9.8AI | CriticalAI | 2026-04-09 |
| CVE-2025-13970 | OpenPLC_V3 Cross-Site Request Forgery CWE-352 | 8.0 | High | 2025-12-13 |
| CVE-2025-53476 | OpenPLC 安全漏洞 CWE-775 | 5.3 | Medium | 2025-10-07 |
| CVE-2025-54811 | OpenPLC_V3 CWE-758 | 7.1 | High | 2025-10-01 |
| CVE-2025-54962 | OpenPLC Runtime version 3 代码问题漏洞 CWE-434 | 6.4 | Medium | 2025-08-04 |
| CVE-2024-36981 | OpenPLC 缓冲区错误漏洞 CWE-125 | 7.5 | High | 2024-09-18 |
| CVE-2024-36980 | OpenPLC 缓冲区错误漏洞 CWE-125 | 7.5 | High | 2024-09-18 |
| CVE-2024-34026 | OpenPLC 安全漏洞 CWE-121 | 9.0 | Critical | 2024-09-18 |
| CVE-2024-39589 | OpenPLC 代码问题漏洞 CWE-704 | 7.5 | High | 2024-09-18 |
| CVE-2024-39590 | OpenPLC 代码问题漏洞 CWE-704 | 7.5 | High | 2024-09-18 |
All 13 known CVE vulnerabilities affecting OpenPLC_V3 with full Chinese analysis, references, and POCs where available.