Olive Design maintains a focused portfolio centered on web-based content and personal-information applications, including its Blog and Diary products, with a durable signal pointing to web-tier input-handling issues. The recurring vulnerability class centers on cross-site scripting flaws arising from improper neutralization of user input during page generation, a pattern typical of web applications where output encoding boundaries require careful management. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Olive Design over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7841MEDIUM Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web script or HTML via the page parameter. | Apr 28, 2017 | 6.1 | 19 | NO | NO |
CVE-2016-7840MEDIUM Cross-site scripting vulnerability in WEB SCHEDULE allows remote attackers to inject arbitrary web script or HTML via the month parameter. | Apr 28, 2017 | 6.1 | 19 | NO | NO |
CVE-2016-7839MEDIUM Cross-site scripting vulnerability in Olive Blog allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Apr 28, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Olive Design.
Media articles that mention a CVE ID that affects a product developed by Olive Design — matched by CVE ID, not by vendor name.