Rockoa maintains a focused product line centered on its core platforms and associated offerings, with a vulnerability footprint that punches above its narrow portfolio size. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the web-application and code-execution nature of its recurring exposure. The durable signal concentrates in weakness classes endemic to dynamic web platforms: SQL injection, cross-site scripting, code injection, unrestricted file upload, and cross-site request forgery—a pattern indicating insufficient input validation, output encoding, and request authentication across the application tier. Defenders deploying these products should prioritize patching for critical disclosures and enforce strong network isolation and web-application firewall rules; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rockoa over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1773CRITICAL A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of the component Configuration Fi | Mar 31, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-18716CRITICAL SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php. | Feb 5, 2021 | 9.8 | 30 | NO | NO |
CVE-2025-63742CRITICAL SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, includi | Dec 9, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-1501HIGH A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL. The manipulation of the argum | Mar 19, 2023 | 8.8 | 28 | NO | NO |
CVE-2020-20593HIGH A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account. | Dec 22, 2021 | 8.0 | 26 | NO | NO |
CVE-2023-49363CRITICAL Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php. | Dec 13, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-7327HIGH A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/openapi/openmodhetongAction.php | Jul 31, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-48930CRITICAL xinhu xinhuoa 2.2.1 contains a File upload vulnerability. | Dec 6, 2023 | 9.8 | 24 | NO | NO |
CVE-2022-45041HIGH SQL Injection exits in xinhu < 2.5.0 | Dec 19, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-18714CRITICAL SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function. | Feb 5, 2021 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rockoa.
Media articles that mention a CVE ID that affects a product developed by Rockoa — matched by CVE ID, not by vendor name.