SecAlerts
O

OpenReception

Security Risk Profile

52
/100
medium

Security Risk Score

Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 6, 2026 to present

15
Total CVEs
7
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
52/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
5
High
2
Medium
6
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
CSRF
1
2
Race Condition
1
3
XSS
1
4
Infoleak
1

Most Affected Products

1. OpenReception appointment booking software9
2. OpenReception OpenReception appointment booking software3
3. OpenReception Appointment booking platform2
4. OpenReception OpenReception1

Recent Vulnerabilities

See more →
CVE-2026-54460
CVSS 9.8critical

OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover

Sep 17, 2026🔧 No Patch
CVE-2026-48088
CVSS 9.4critical

OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory

Aug 6, 2026🔧 No Patch
CVE-2026-48087
CVSS 9.8critical

OpenReception: WebAuthn passkey injection allows account takeover

Aug 6, 2026🔧 No Patch
CVE-2026-48086
CVSS 9.9critical

OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN

Aug 6, 2026🔧 No Patch
CVE-2026-48085
CVSS 9.8critical

OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap

Aug 6, 2026🔧 No Patch
CVE-2026-48083
CVSS 6.5medium

OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits

Aug 6, 2026🔧 No Patch
CVE-2026-48082
CVSS 3.7low

OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplification

Aug 6, 2026🔧 No Patch
CVE-2026-48081
CVSS 8.1high

OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer

Aug 6, 2026🔧 No Patch
CVE-2026-48079
CVSS 7.4high

OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry

Aug 6, 2026🔧 No Patch
CVE-2026-48078
CVSS 5.3medium

OpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callers

Aug 6, 2026🔧 No Patch

Monitor OpenReception in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

OpenReception Security Vulnerabilities & Risk Score | 15 CVEs | SecAlerts - SecAlerts