Oscss maintains a narrowly scoped web-based tool product, with observed vulnerabilities clustering around path-traversal and cross-site-scripting issues typical of web application input handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oscss over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4713MEDIUM Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) | Dec 8, 2011 | 5.0 | 26 | NO | YES |
CVE-2010-2856MEDIUM Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbitrary web script or HTML via t | Jul 25, 2010 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oscss.
Media articles that mention a CVE ID that affects a product developed by Oscss — matched by CVE ID, not by vendor name.