Hailey888's vulnerability footprint centers on an OA (office automation) system product, with a durable signal in web application input-handling issues spanning cross-site scripting and code injection weaknesses. These are recurring classes in web-facing administrative and productivity software, reflecting the parsing and output-encoding demands of dynamic content generation in such systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hailey888 over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3388MEDIUM A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller | Apr 7, 2025 | 6.1 | 20 | NO | NO |
CVE-2025-3390MEDIUM A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controlle | Apr 8, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-3389MEDIUM A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/con | Apr 8, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-29691MEDIUM A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userNam | May 14, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-29690MEDIUM A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype | May 14, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-29689MEDIUM A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the passwor | May 14, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-29688MEDIUM A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title p | May 14, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-29686MEDIUM A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title p | May 14, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-3392MEDIUM A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the file cn/gson/oasys/controller/ma | Apr 8, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-3391MEDIUM A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function outAddress of the file cn/gson/ | Apr 8, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hailey888.
Media articles that mention a CVE ID that affects a product developed by Hailey888 — matched by CVE ID, not by vendor name.