{"id":"CVE-2026-52370","published":"2026-08-04T22:17:15.610","lastModified":"2026-08-05T20:17:09.530","description":"A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.","cvssScore":6.1,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/RichardKabuto/CVE-2026-52370/issues/1","tags":[]},{"url":"https://www.o2oa.net/download.html","tags":[]}],"exploitRefs":[{"url":"https://github.com/RichardKabuto/CVE-2026-52370/issues/1","tags":[]}],"hasPoc":true,"ai":null}