Oxwall is a social networking and community platform whose vulnerability profile centers on web application input and request handling. The recurring weakness classes affecting the product are cross-site request forgery and cross-site scripting, typical of web platforms where user-supplied content and inter-request validation are critical; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oxwall over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5534MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators for requests that (1) put the | Nov 2, 2015 | 6.8 | 27 | NO | YES |
CVE-2014-9101MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authenticati | Nov 26, 2014 | 6.8 | 27 | NO | YES |
CVE-2012-4928MEDIUM Cross-site scripting (XSS) vulnerability in ow_updates/index.php in Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the plugin parameter. | Sep 15, 2012 | 4.3 | 24 | NO | YES |
CVE-2012-0872MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in OxWall 1.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) captchaField, (2) email, ( | Mar 19, 2012 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oxwall.
Media articles that mention a CVE ID that affects a product developed by Oxwall — matched by CVE ID, not by vendor name.