O2OA vulnerabilities
CVEs whose affected-version data names the O2OA package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-97179Medium· 4.3A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2
A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of …
▾ Sunlitvia NVD
CVE-2022-22916Critical· 9.8PoCO2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
▾ Abyssalzoneland · o2oaEPSS 39%via NVD