Osclass is a niche open-source classifieds platform whose vulnerability footprint concentrates in its single self-hosted application product and centers on application-layer weaknesses: path traversal, cross-site scripting, SQL injection, and unrestricted file uploads. These vulnerabilities are characteristic of web applications that handle user input and file handling, and the exposure carries an elevated tendency toward public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osclass over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6308MEDIUM Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/in | Oct 20, 2014 | 5.0 | 48 | NO | YES |
CVE-2012-0973HIGH Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not prope | Sep 25, 2012 | 7.5 | 32 | NO | YES |
CVE-2016-10751HIGH osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an ima | May 24, 2019 | 7.2 | 25 | NO | NO |
CVE-2018-14481MEDIUM Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280. | Jan 3, 2019 | 6.1 | 21 | NO | NO |
CVE-2014-8084HIGH Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary local files via a .. ( | Jan 5, 2015 | 7.5 | 20 | NO | NO |
CVE-2014-8083HIGH SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search | Jan 5, 2015 | 7.5 | 20 | NO | NO |
CVE-2012-5162MEDIUM Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) edit | Sep 26, 2012 | 6.5 | 20 | NO | NO |
CVE-2014-8085MEDIUM Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute a | Jan 5, 2015 | 6.8 | 18 | NO | NO |
CVE-2014-6280MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action or (2) nsextt parameter | Oct 20, 2014 | 4.3 | 18 | NO | NO |
CVE-2012-5163MEDIUM Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an | Sep 26, 2012 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osclass.
Media articles that mention a CVE ID that affects a product developed by Osclass — matched by CVE ID, not by vendor name.