← Back

Rockoa

rockoa

28 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Rockoa
rockoa
Xinhu
xinhu

CVEs (28)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rockoa
1Xinhu
Jun 17, 2026
Dec 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL Injection exits in xinhu < 2.5.0
1Rockoa
1Rockoa
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
1Rockoa
1Rockoa
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
1Rockoa
1Rockoa
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.
1Rockoa
1Rockoa
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php
1Rockoa
1Rockoa
Jun 17, 2026
Jan 26, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the administrator and execute JavaScript code, because webmain/flow/input/mode_emailmAction....Show more
RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the administrator and execute JavaScript code, because webmain/flow/input/mode_emailmAction.php does not perform strict filtering.Show less
1Rockoa
1Xinhu
Jun 17, 2026
Dec 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.
1Rockoa
1Rockoa
Jun 17, 2026
Jun 28, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka...Show more
RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.Show less