CVE-2026-2074
- EPSS 0.27%
- Veröffentlicht 07.02.2026 04:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possibl...
CVE-2025-9737
- EPSS 0.33%
- Veröffentlicht 31.08.2025 16:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page. Performing manipulation of the argument description/applicationName/...
CVE-2025-9736
- EPSS 0.33%
- Veröffentlicht 31.08.2025 16:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName...
CVE-2025-9735
- EPSS 0.26%
- Veröffentlicht 31.08.2025 15:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in O2OA up to 10.0-410. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName...
CVE-2025-9734
- EPSS 0.33%
- Veröffentlicht 31.08.2025 15:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in O2OA up to 10.0-410. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal Profile Page. The manipulation of the argument name/alias/description/...
CVE-2025-9719
- EPSS 0.26%
- Veröffentlicht 31.08.2025 06:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_processplatform_assemble_designer/jaxrs/script of the component Personal Profile Page. Executing manipulation of the argument name/alias/des...
CVE-2025-9718
- EPSS 0.33%
- Veröffentlicht 31.08.2025 05:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in O2OA up to 10.0-410. This affects an unknown part of the file /x_processplatform_assemble_designer/jaxrs/process of the component Personal Profile Page. Performing manipulation of the argument name/alias results...
CVE-2025-9717
- EPSS 0.26%
- Veröffentlicht 31.08.2025 05:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_organization_assemble_control/jaxrs/unit/ of the component Personal Profile Page. Such manipulation of the argument name/shortN...
CVE-2025-9716
- EPSS 0.3%
- Veröffentlicht 31.08.2025 04:32:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was determined in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_processplatform_assemble_designer/jaxrs/form of the component Personal Profile Page. This manipulation of the argument na...
CVE-2025-9715
- EPSS 0.32%
- Veröffentlicht 31.08.2025 00:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_cms_assemble_control/jaxrs/script of the component Personal Profile Page. The manipulation of the argument name/alias/description results in cross site s...