o-dyn CVE Vulnerabilities & Metrics

Focus on o-dyn vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About o-dyn Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with o-dyn. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total o-dyn CVEs: 9
Earliest CVE date: 17 Nov 2010, 01:00 UTC
Latest CVE date: 22 Oct 2024, 17:15 UTC

Latest CVE reference: CVE-2024-48708

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 4

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical o-dyn CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.23

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 8
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS o-dyn CVEs

These are the five CVEs with the highest CVSS scores for o-dyn, sorted by severity first and recency.

All CVEs for o-dyn

CVE-2024-48708 o-dyn vulnerability CVSS: 0 22 Oct 2024, 17:15 UTC

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.

CVE-2024-48707 o-dyn vulnerability CVSS: 0 22 Oct 2024, 17:15 UTC

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.

CVE-2024-48706 o-dyn vulnerability CVSS: 0 22 Oct 2024, 17:15 UTC

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.

CVE-2024-46240 o-dyn vulnerability CVSS: 0 22 Oct 2024, 16:15 UTC

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.

CVE-2021-3298 o-dyn vulnerability CVSS: 3.5 29 Jan 2021, 06:15 UTC

Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.

CVE-2020-13655 o-dyn vulnerability CVSS: 4.3 31 Aug 2020, 15:15 UTC

An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.

CVE-2015-0258 o-dyn vulnerability CVSS: 6.5 17 Feb 2020, 18:15 UTC

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.

CVE-2013-5027 o-dyn vulnerability CVSS: 7.5 27 Dec 2019, 18:15 UTC

Collabtive 1.0 has incorrect access control

CVE-2019-8935 o-dyn vulnerability CVSS: 3.5 19 Feb 2019, 15:29 UTC

Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.

CVE-2014-3247 o-dyn vulnerability CVSS: 4.3 15 May 2014, 14:55 UTC

Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.

CVE-2014-3246 o-dyn vulnerability CVSS: 6.5 13 May 2014, 14:55 UTC

SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php.

CVE-2013-6872 o-dyn vulnerability CVSS: 6.5 21 Jan 2014, 15:17 UTC

SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action.

CVE-2010-5285 o-dyn vulnerability CVSS: 6.8 26 Nov 2012, 23:55 UTC

Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action.

CVE-2010-5284 o-dyn vulnerability CVSS: 4.3 26 Nov 2012, 23:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to manageajax.php, and the (3) pic parameter to thumb.php.

CVE-2012-2670 o-dyn vulnerability CVSS: 6.5 17 Jun 2012, 03:41 UTC

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

CVE-2010-4269 o-dyn vulnerability CVSS: 7.5 17 Nov 2010, 01:00 UTC

SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID] cookie in a pull action.