Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Osclass

First CVE: Sep 25, 2012Active for: 14 yearsTotal CVEs: 10
44.2
VTI Score
High

Osclass is a niche open-source classifieds platform whose vulnerability footprint concentrates in its single self-hosted application product and centers on application-layer weaknesses: path traversal, cross-site scripting, SQL injection, and unrestricted file uploads. These vulnerabilities are characteristic of web applications that handle user input and file handling, and the exposure carries an elevated tendency toward public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Osclass over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 25, 2012
13 years ago
Most Recent CVE
May 24, 2019
2,618 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-6308MEDIUM
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/in
Oct 20, 20145.048NOYES
CVE-2012-0973HIGH
Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not prope
Sep 25, 20127.532NOYES
CVE-2016-10751HIGH
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an ima
May 24, 20197.225NONO
CVE-2018-14481MEDIUM
Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.
Jan 3, 20196.121NONO
CVE-2014-8084HIGH
Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary local files via a .. (
Jan 5, 20157.520NONO
CVE-2014-8083HIGH
SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search
Jan 5, 20157.520NONO
CVE-2012-5162MEDIUM
Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) edit
Sep 26, 20126.520NONO
CVE-2014-8085MEDIUM
Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute a
Jan 5, 20156.818NONO
CVE-2014-6280MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action or (2) nsextt parameter
Oct 20, 20144.318NONO
CVE-2012-5163MEDIUM
Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an
Sep 26, 20124.316NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (20.0%)
Unknown8 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (20.0%)
High0 (0.0%)
Unknown8 (80.0%)
User Interaction
None1 (10.0%)
Unknown8 (80.0%)
Required1 (10.0%)
Privileges Required
Low0 (0.0%)
High1 (10.0%)
None1 (10.0%)
Unknown8 (80.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 96th percentile
ExploitDB
2 CVEs
20.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Osclass.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Osclass — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Osclass's Products

View all 1 CNAs →

Top CWEs