Osqa is a question-and-answer platform with a niche but above-typical footprint in the vulnerability landscape, and the observed disclosures center on its core product. The durable signal is input-handling weakness in web-facing contexts, specifically improper neutralization of user input during page generation leading to cross-site scripting. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osqa over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1782MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar | Mar 19, 2012 | 4.3 | 23 | NO | YES |
CVE-2012-1245MEDIUM Cross-site scripting (XSS) vulnerability in the cleanup_urls function in forum/utils/html.py in OSQA before 1234, and 0.9.0 Beta 3 and earlier, allows remote attackers to inject ar | Apr 27, 2012 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osqa.
Media articles that mention a CVE ID that affects a product developed by Osqa — matched by CVE ID, not by vendor name.