Skip to main content

Vendor/product archive

zoneland / o2oa CVEs

Beta · best-effort

25 CVEs tagged to zoneland / o2oa2 Critical, 1 High, 3 Medium, 19 Low, 0 Unrated.

CVE-2026-2074

Published Feb 7, 2026

A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler.…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-9737

Published Aug 31, 2025

A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Pag…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9736

Published Aug 31, 2025

A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Persona…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9735

Published Aug 31, 2025

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page.…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9734

Published Aug 31, 2025

A security flaw has been discovered in O2OA up to 10.0-410. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9719

Published Aug 31, 2025

A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_processplatform_assemble_designer/jaxrs/script of the component Perso…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9718

Published Aug 31, 2025

A security flaw has been discovered in O2OA up to 10.0-410. This affects an unknown part of the file /x_processplatform_assemble_designer/jaxrs/process of the component Personal P…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9717

Published Aug 31, 2025

A vulnerability was identified in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_organization_assemble_control/jaxrs/unit/ of the compone…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9716

Published Aug 31, 2025

A vulnerability was determined in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_processplatform_assemble_designer/jaxrs/form of th…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9715

Published Aug 31, 2025

A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_cms_assemble_control/jaxrs/script of the component Personal Profile Page. The mani…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9683

Published Aug 30, 2025

A vulnerability was found in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_cms_assemble_control/jaxrs/form of the component Personal Pro…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9682

Published Aug 30, 2025

A vulnerability has been found in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_cms_assemble_control/jaxrs/design/appdict of the c…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9681

Published Aug 30, 2025

A flaw has been found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_program_center/jaxrs/agent of the component Personal Profile Page. Executing manipulat…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9680

Published Aug 30, 2025

A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Pe…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9659

Published Aug 29, 2025

A vulnerability has been found in O2OA up to 10.0-410. The affected element is an unknown function of the file /x_portal_assemble_designer/jaxrs/widget of the component Personal P…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9658

Published Aug 29, 2025

A flaw has been found in O2OA up to 10.0-410. Impacted is an unknown function of the file /x_portal_assemble_designer/jaxrs/dict/ of the component Personal Profile Page. This mani…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9657

Published Aug 29, 2025

A vulnerability was detected in O2OA up to 10.0-410. This issue affects some unknown processing of the file /x_program_center/jaxrs/script of the component Personal Profile Page.…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9655

Published Aug 29, 2025

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble_control/jaxrs/person/ of the component Personal Profile Pa…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9646

Published Aug 29, 2025

A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_organization_assemble_personal/jaxrs/definition/calendarConfig.…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-37777

Published Aug 27, 2025

O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22994

Published Jan 31, 2025

O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-35591

Published May 24, 2024

An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3689

Published Apr 12, 2024

A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_as…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-47418

Published Nov 30, 2023

Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-22916

Published Feb 17, 2022

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1