Osteopathic appears in the vulnerability record primarily through a downloadable resource associated with the American Osteopathic Association, though the specific technical nature and scope of this offering remain unclear from available disclosure data. The sparse vulnerability signal centers on insufficient information classifications, which suggests either minimal public disclosure detail or limited applicable weakness-class specificity; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osteopathic over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13617HIGH The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the s | Mar 25, 2025 | 8.6 | 24 | NO | NO |
CVE-2024-13618HIGH The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requ | Mar 25, 2025 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osteopathic.
Media articles that mention a CVE ID that affects a product developed by Osteopathic — matched by CVE ID, not by vendor name.