Ocproducts operates a focused web content management and collaboration platform, Composr, that presents a concentrated vulnerability surface around file-handling and content-generation mechanisms. The durable signal in the vendor's disclosures centers on dangerous file-upload handling and cross-site scripting weaknesses that are characteristic of web-application input and output processing; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ocproducts over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30149CRITICAL Composr 10.0.36 allows upload and execution of PHP files. | Apr 6, 2021 | 9.8 | 45 | NO | YES |
CVE-2021-46360HIGH Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.ph | Feb 9, 2022 | 8.8 | 42 | NO | YES |
CVE-2021-30150MEDIUM Composr 10.0.36 allows XSS in an XML script. | Apr 6, 2021 | 6.1 | 31 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ocproducts.
Media articles that mention a CVE ID that affects a product developed by Ocproducts — matched by CVE ID, not by vendor name.