Aggregates CVE and security vulnerability intelligence across all olive_design-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk cross-site scripting; exposure may include vendor impact session compromise in vendor surface production workloads and vendor surface software deployment contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2016-7841 | Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web script or HTML via the page parameter. | [email protected] | 6.1 | 0.89% | 2017-04-28 | 2026-05-13 |
| CVE-2016-7840 | Cross-site scripting vulnerability in WEB SCHEDULE allows remote attackers to inject arbitrary web script or HTML via the month parameter. | [email protected] | 6.1 | 0.85% | 2017-04-28 | 2026-05-13 |
| CVE-2016-7839 | Cross-site scripting vulnerability in Olive Blog allows remote attackers to inject arbitrary web script or HTML via the search parameter. | [email protected] | 6.1 | 0.89% | 2017-04-28 | 2026-05-13 |