PatchSiren

O2OA CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM O2OA CVE published 2026-08-04

CVE-2026-52370

CVE-2026-52370 is a reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10. This vulnerability allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL. The CVE record was published on 2026-08-04T22:17:15.610Z and has not been modified since then. Organizations should review and verify their deployments for potential re [truncated]