Openplcproject
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Openplcproject product.
RSS Feeds for Openplcproject security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Openplcproject products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Openplcproject Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 2 vulnerabilities in Openplcproject with an average score of 8.7 out of ten. Last year, in 2025 Openplcproject had 1 security vulnerability published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.60.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 8.70 |
| 2025 | 1 | 7.10 |
| 2024 | 5 | 7.96 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 3 | 6.53 |
It may take a day or so for new Openplcproject vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Openplcproject Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-11826 | Jul 18, 2026 |
OpenPLC v3 Heap BF in getData() Enables DOSOpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In parseConfig() the function is invoked with the 100-byte heap-allocated MB_device.dev_name field. An authenticated attacker with access to the OpenPLC web interface can send a crafted HTTP POST to the /modbus endpoint with an oversized device_name value; the value is persisted to mbconfig.cfg and parsed on load, overflowing dev_name and overwriting adjacent struct fields (protocol at offset 108, dev_address at offset 109, ip_port at offset 210). A 200-byte payload writes 100 bytes past the allocation. The result is heap corruption leading to runtime crash and denial of service of the PLC process control loop, with attacker-controlled overwrite of adjacent configuration fields. The upstream repository was archived on 2026-04-04 and no fix is expected; the vendor has confirmed the issue does not affect OpenPLC Runtime v4. |
|
| CVE-2021-47770 | Jan 21, 2026 |
OpenPLC v3 RCE via Authenticated Hardware Config InterfaceOpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that establishes a network connection to a specified IP and port, enabling remote command execution. |
|
| CVE-2025-34226 | Oct 03, 2025 |
OpenPLC Runtime v3 /upload-program-action Input Validation DoSOpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate until a restart; on restart the runtime can fail to start because of corrupted database entries, resulting in persistent denial of service requiring complete rebase of the product to recover. This vulnerability was remediated by commit 095ee09. |
|
| CVE-2024-39590 | Sep 18, 2024 |
OpenPLC Runtime EtherNet/IP PRDLR Pointer Deref DoSMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the `Protected_Logical_Write_Reply` function |
|
| CVE-2024-39589 | Sep 18, 2024 |
OpenPLC EtherNet/IP parser Ptr deref ProtectedLogicalReadReply Leading to DoSMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the `Protected_Logical_Read_Reply` function |
|
| CVE-2024-36981 | Sep 18, 2024 |
OpenPLC Runtime EtherNet/IP OOB Read DoS VulnerabilityAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is the final instance of the incorrect comparison. |
|
| CVE-2024-36980 | Sep 18, 2024 |
OOB Read in OpenPLC EtherNet/IP PCCC Parser Causes DoSAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is the first instance of the incorrect comparison. |
|
| CVE-2024-34026 | Sep 18, 2024 |
OpenPLC v3 Buffer Overflow in EtherNet/IP Parser Enables RCEA stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability. |
|
| CVE-2021-3351 | Aug 02, 2021 |
OpenPLC runtime V3 through 2016-03-14OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page. |
|
| CVE-2021-26829 | Jun 11, 2021 |
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on WindowsOpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. |
|