Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rockoa

First CVE: Jun 28, 2019Active for: 7 yearsTotal CVEs: 28
34.8
VTI Score
Medium

Rockoa maintains a focused product line centered on its core platforms and associated offerings, with a vulnerability footprint that punches above its narrow portfolio size. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the web-application and code-execution nature of its recurring exposure. The durable signal concentrates in weakness classes endemic to dynamic web platforms: SQL injection, cross-site scripting, code injection, unrestricted file upload, and cross-site request forgery—a pattern indicating insufficient input validation, output encoding, and request authentication across the application tier. Defenders deploying these products should prioritize patching for critical disclosures and enforce strong network isolation and web-application firewall rules; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rockoa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2019
7 years ago
Most Recent CVE
Jan 5, 2026
200 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1773CRITICAL
A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of the component Configuration Fi
Mar 31, 20239.830NONO
CVE-2020-18716CRITICAL
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
Feb 5, 20219.830NONO
CVE-2025-63742CRITICAL
SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, includi
Dec 9, 20259.829NONO
CVE-2023-1501HIGH
A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL. The manipulation of the argum
Mar 19, 20238.828NONO
CVE-2020-20593HIGH
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
Dec 22, 20218.026NONO
CVE-2023-49363CRITICAL
Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.
Dec 13, 20239.825NONO
CVE-2024-7327HIGH
A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/openapi/openmodhetongAction.php
Jul 31, 20248.824NONO
CVE-2023-48930CRITICAL
xinhu xinhuoa 2.2.1 contains a File upload vulnerability.
Dec 6, 20239.824NONO
CVE-2022-45041HIGH
SQL Injection exits in xinhu < 2.5.0
Dec 19, 20227.524NONO
CVE-2020-18714CRITICAL
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.
Feb 5, 20219.824NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
46%
29%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (96.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.6%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (67.9%)
Unknown0 (0.0%)
Required9 (32.1%)
Privileges Required
Low10 (35.7%)
High1 (3.6%)
None17 (60.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rockoa.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rockoa — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rockoa's Products

View all 2 CNAs →

Top CWEs