Known Vulnerabilities for products from Rockoa
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Rockoa".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-0588 json | A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functionali... | Not Provided | 2026-01-05 | 2026-04-29 |
| CVE-2026-0587 json | A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file rock_pa... | Not Provided | 2026-01-05 | 2026-04-29 |
| CVE-2025-9602 json | A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Perfor... | Not Provided | 2025-08-29 | 2026-04-29 |
| CVE-2023-5297 json | A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of th... | 7.5 - HIGH | 2023-09-29 | 2023-11-07 |
| CVE-2023-5296 json | A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some u... | 7.5 - HIGH | 2023-09-29 | 2023-11-07 |
| CVE-2023-1773 json | A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the f... | 9.8 - CRITICAL | 2023-03-31 | 2023-11-07 |
| CVE-2023-1501 json | A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file... | 8.8 - HIGH | 2023-03-19 | 2023-11-07 |
| CVE-2022-45041 json | SQL Injection exits in xinhu < 2.5.0 | 7.5 - HIGH | 2022-12-19 | 2022-12-23 |
| CVE-2020-35388 json | rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which th... | 7.5 - HIGH | 2020-12-26 | 2020-12-29 |
| CVE-2020-21147 json | RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code ... | 4.8 - MEDIUM | 2021-01-26 | 2021-01-29 |
| CVE-2020-20593 json | A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator acc... | 8 - HIGH | 2021-12-22 | 2021-12-28 |
| CVE-2020-18716 json | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.... | 9.8 - CRITICAL | 2021-02-05 | 2021-02-05 |
| CVE-2020-18714 json | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.p... | 9.8 - CRITICAL | 2021-02-05 | 2021-02-05 |
| CVE-2020-18713 json | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAct... | 9.8 - CRITICAL | 2021-02-05 | 2021-02-05 |
| CVE-2019-9846 json | RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore me... | 8.8 - HIGH | 2019-06-28 | 2019-07-05 |