VYPR
Vendor

Zoneland

Products
1
CVEs
25
Across products
25
Status
Private

Products

1

Recent CVEs

25
View all 25 CVEs →
  • CVE-2022-22916CriFeb 17, 2022
    risk 0.67cvss 9.8epss 0.38

    O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

  • CVE-2023-47418CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.

  • CVE-2024-37777HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.01

    O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.

  • CVE-2026-2074MedFeb 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to initiate the attack…

  • CVE-2025-22994MedJan 31, 2025
    risk 0.40cvss 6.1epss 0.00

    O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.

  • CVE-2024-35591MedMay 24, 2024
    risk 0.35cvss 5.4epss 0.00

    An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2024-3689LowApr 12, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-4-43f4fe3. The manipulation leads to information…

  • CVE-2025-9737LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page. Performing manipulation of the argument description/applicationName/queryName results in cross…

  • CVE-2025-9736LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName leads to cross site…

  • CVE-2025-9735LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in O2OA up to 10.0-410. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName causes cross site scripting.…

  • CVE-2025-9734LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in O2OA up to 10.0-410. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal Profile Page. The manipulation of the argument name/alias/description/applicationName results in…

  • CVE-2025-9719LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_processplatform_assemble_designer/jaxrs/script of the component Personal Profile Page. Executing manipulation of the argument name/alias/description/applicationName can…

  • CVE-2025-9718LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in O2OA up to 10.0-410. This affects an unknown part of the file /x_processplatform_assemble_designer/jaxrs/process of the component Personal Profile Page. Performing manipulation of the argument name/alias results in cross site scripting.…

  • CVE-2025-9717LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_organization_assemble_control/jaxrs/unit/ of the component Personal Profile Page. Such manipulation of the argument name/shortName/distinguishedName/pinyin/p…

  • CVE-2025-9716LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_processplatform_assemble_designer/jaxrs/form of the component Personal Profile Page. This manipulation of the argument name/alias/description causes…

  • CVE-2025-9715LowAug 31, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_cms_assemble_control/jaxrs/script of the component Personal Profile Page. The manipulation of the argument name/alias/description results in cross site scripting. The attack can be…

  • CVE-2025-9683LowAug 30, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_cms_assemble_control/jaxrs/form of the component Personal Profile Page. The manipulation results in cross site scripting. The attack may be launched remotely.…

  • CVE-2025-9682LowAug 30, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_cms_assemble_control/jaxrs/design/appdict of the component Personal Profile Page. The manipulation leads to cross site scripting. The attack may be…

  • CVE-2025-9681LowAug 30, 2025
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_program_center/jaxrs/agent of the component Personal Profile Page. Executing manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been…

  • CVE-2025-9680LowAug 30, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Performing manipulation results in cross site scripting. The attack can be initiated remotely. The…