zsx
6 exploits
Active since Feb 2018
OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File
CVSS 7.3
OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
CVSS 9.1
OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches
CVSS 6.8
OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel Setup
CVSS 8.8
OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes
CVSS 7.7
Zblogcn Z-blogphp - CSRF
CVSS 6.5