zsx
8 exploits
Active since Feb 2018
OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool Access
CVSS 7.1
OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get
CVSS 4.3
OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File
CVSS 7.3
OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
CVSS 9.1
OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches
CVSS 6.8
OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel Setup
CVSS 8.8
OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes
CVSS 7.7
Z-BlogPHP 1.5.1 - Cross-Site Request Forgery via AppCentre Plugin Deletion
CVSS 6.5