AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-52370

MEDIUM · CVSS 6.1 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Forum posting function in O2OA v10 is vulnerable to reflected cross-site scripting (XSS), enabling attackers to execute arbitrary JavaScript in the victim's browser through a specially crafted URL. This could lead to session hijacking, data theft, or other malicious actions. Organizations utilizing O2OA v10 should prioritize addressing this vulnerability to protect their users from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52370
Severity
MEDIUM
CVSS
6.1
EPSS
0.19%
Java

Original NVD Description

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.