CVE-2026-52370: XSS
Published Aug 4, 2026
·Updated
A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.
Affected Software
1 affected component
O2OA O2OA=10
Event History
Aug 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-52370?
The severity of CVE-2026-52370 is rated at risk 37.
2
How do I fix CVE-2026-52370?
To fix CVE-2026-52370, update to the latest version of O2OA that addresses this reflected XSS vulnerability.
3
What types of attacks can exploit CVE-2026-52370?
CVE-2026-52370 can be exploited through reflected cross-site scripting attacks, allowing attackers to execute arbitrary JavaScript in victims' browsers.
4
Which software is affected by CVE-2026-52370?
CVE-2026-52370 affects O2OA version 10.
5
When was CVE-2026-52370 published?
CVE-2026-52370 was published on August 4, 2026.