Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

O2OA — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in O2OA, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses associated with the O2OA product developed by O2Team. It aggregates vulnerability data relevant to the open-source enterprise application platform, focusing on common weakness types such as injection flaws, cross-site scripting, and access control issues found within its architecture. The collected records cover vulnerabilities reported and disclosed between 2019 and 2024, providing a comprehensive historical view of security incidents affecting this specific software suite. Visitors to this page can track O2Team’s official security advisories over time, gaining insight into how the vendor responds to emerging threats. Users can also deepen their understanding of specific weakness classes as they manifest in O2OA’s codebase, helping developers and administrators identify patterns in reported bugs. Additionally, the page allows stakeholders to look up the vulnerability history of O2OA versions, supporting risk assessments and patch management decisions. By consolidating these details, the resource offers a centralized reference for security professionals evaluating the platform’s security posture. This aggregation does not include marketing claims or promotional content, but rather focuses strictly on factual vulnerability records. The goal is to aid in the mitigation of risks by providing clear, accessible information about past and present security challenges. Readers can use this data to inform their own security strategies, ensuring that known issues are addressed proactively. The information presented here is intended to support technical decision-making rather than serve as a definitive security guarantee.

Vendor: Zhejiang Land Zongheng Network Technology

CVE ID Title CVSS Severity Published
CVE-2026-7292 o2oa NodeAgent NodeAgent.java syncFile improper authorization CWE-285 5.6 Medium 2026-04-28
CVE-2026-7291 o2oa URL Fetching FileAction.java FileAction server-side request forgery CWE-918 6.3 Medium 2026-04-28
CVE-2026-2074 O2OA HTTP POST Request check xml external entity reference CWE-611 6.3 Medium 2026-02-07
CVE-2025-9737 O2OA Personal Profile importmodel cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9736 O2OA Personal Profile statement cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9735 O2OA Personal Profile table cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9734 O2OA Personal Profile stat cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9719 O2OA Personal Profile script cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9718 O2OA Personal Profile process cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9717 O2OA Personal Profile unit cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9716 O2OA Personal Profile form cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9715 O2OA Personal Profile script cross site scripting CWE-79 3.5 Low 2025-08-31
CVE-2025-9683 O2OA Personal Profile form cross site scripting CWE-79 3.5 Low 2025-08-30
CVE-2025-9682 O2OA Personal Profile appdict cross site scripting CWE-79 3.5 Low 2025-08-30
CVE-2025-9681 O2OA Personal Profile agent cross site scripting CWE-79 3.5 Low 2025-08-30
CVE-2025-9680 O2OA Personal Profile page cross site scripting CWE-79 3.5 Low 2025-08-30
CVE-2025-9659 O2OA Personal Profile widget cross site scripting CWE-79 3.5 Low 2025-08-29
CVE-2025-9658 O2OA Personal Profile dict cross site scripting CWE-79 3.5 Low 2025-08-29
CVE-2025-9657 O2OA Personal Profile script cross site scripting CWE-79 3.5 Low 2025-08-29
CVE-2025-9655 O2OA Personal Profile person cross site scripting CWE-79 3.5 Low 2025-08-29
CVE-2025-9646 O2OA calendarConfig cross site scripting CWE-79 3.5 Low 2025-08-29
CVE-2024-3689 Zhejiang Land Zongheng Network Technology O2OA information disclosure CWE-200 3.7 Low 2024-04-12

All 22 known CVE vulnerabilities affecting O2OA with full Chinese analysis, references, and POCs where available.