Hustoj is a niche online judge and competitive programming platform with a focused vulnerability profile centered on its core product. The durable signal reflects the platform's web-facing nature and recurs through input-handling and file-access weakness classes including cross-site scripting, path traversal, and improper CSV formula neutralization. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hustoj over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24479CRITICAL HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.ph | Jan 27, 2026 | 9.8 | 54 | NO | YES |
CVE-2026-23873CRITICAL hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the cont | Jan 22, 2026 | 9.0 | 27 | NO | NO |
CVE-2022-42187MEDIUM Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php. | Nov 17, 2022 | 6.1 | 22 | NO | NO |
CVE-2025-50938MEDIUM Cross site scripting (XSS) vulnerability in Hustoj 2025-01-31 via the TID parameter to thread.php. | Aug 19, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hustoj.
Media articles that mention a CVE ID that affects a product developed by Hustoj — matched by CVE ID, not by vendor name.