All 22 CVE vulnerabilities found in O2OA, with AI-generated Chinese analysis, references, and POCs.
This page documents known security weaknesses associated with the O2OA product developed by O2Team. It aggregates vulnerability data relevant to the open-source enterprise application platform, focusing on common weakness types such as injection flaws, cross-site scripting, and access control issues found within its architecture. The collected records cover vulnerabilities reported and disclosed between 2019 and 2024, providing a comprehensive historical view of security incidents affecting this specific software suite. Visitors to this page can track O2Team’s official security advisories over time, gaining insight into how the vendor responds to emerging threats. Users can also deepen their understanding of specific weakness classes as they manifest in O2OA’s codebase, helping developers and administrators identify patterns in reported bugs. Additionally, the page allows stakeholders to look up the vulnerability history of O2OA versions, supporting risk assessments and patch management decisions. By consolidating these details, the resource offers a centralized reference for security professionals evaluating the platform’s security posture. This aggregation does not include marketing claims or promotional content, but rather focuses strictly on factual vulnerability records. The goal is to aid in the mitigation of risks by providing clear, accessible information about past and present security challenges. Readers can use this data to inform their own security strategies, ensuring that known issues are addressed proactively. The information presented here is intended to support technical decision-making rather than serve as a definitive security guarantee.
Vendor: Zhejiang Land Zongheng Network Technology
All 22 known CVE vulnerabilities affecting O2OA with full Chinese analysis, references, and POCs where available.