Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zoneland

First CVE: Feb 17, 2022Active for: 4 yearsTotal CVEs: 25
28.5
VTI Score
Low

Zoneland's vulnerability profile concentrates in its O2OA collaboration and office automation platform, a modestly represented but notably prominent product in the landscape. The vendor's disclosures cluster around application-layer input handling and code generation weaknesses, including cross-site scripting, code injection, exposure of sensitive information, and externally controlled resource references, reflecting the risks inherent to a web-based workflow and content-management system. The recurring pattern of injection and XSS issues suggests a durable structural exposure in how the platform processes and renders user-supplied and external data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zoneland over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2022
4 years ago
Most Recent CVE
Feb 7, 2026
167 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-22916CRITICAL
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
Feb 17, 20229.846NONO
CVE-2024-37777HIGH
O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
Aug 27, 20258.828NONO
CVE-2023-47418CRITICAL
Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.
Nov 30, 20239.827NONO
CVE-2026-2074MEDIUM
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler.
Feb 7, 20266.321NONO
CVE-2025-9734MEDIUM
A security flaw has been discovered in O2OA up to 10.0-410. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal
Aug 31, 20255.421NONO
CVE-2025-9680MEDIUM
A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Per
Aug 30, 20255.421NONO
CVE-2025-9737MEDIUM
A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page
Aug 31, 20255.420NONO
CVE-2025-9736MEDIUM
A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal
Aug 31, 20255.420NONO
CVE-2025-9719MEDIUM
A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_processplatform_assemble_designer/jaxrs/script of the component Person
Aug 31, 20255.420NONO
CVE-2025-9718MEDIUM
A security flaw has been discovered in O2OA up to 10.0-410. This affects an unknown part of the file /x_processplatform_assemble_designer/jaxrs/process of the component Personal Pr
Aug 31, 20255.420NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
88%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None4 (16.0%)
Unknown0 (0.0%)
Required21 (84.0%)
Privileges Required
Low19 (76.0%)
High0 (0.0%)
None6 (24.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zoneland.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zoneland — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zoneland's Products

View all 2 CNAs →

Top CWEs