igniterealtime Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with igniterealtime products.
Products
- Openfire4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-36956MEDIUM | Openfire 4.6.0 - 'path' Stored XSSOpenfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page. CWE-79Jan 26, 2026 | CVSS5.1v4.0 | EPSS0.253% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59154MEDIUM | Openfire allows potential identity spoofing via unsafe CN parsingOpenfire is an XMPP server licensed under the Open Source Apache License. Openfire’s SASL EXTERNAL mechanism for client TLS authentication contains a vulnerability in how it extracts user identities from X.509 certificates. Instead of parsing the structured ASN.1 data, the code calls X509Certificate.getSubjectDN().getName() and applies a regex to look for CN=. This method produces a provider-dependent string that does not escape special characters. In SunJSSE (sun.security.x509.X500Name), for ex… CWE-290Sep 15, 2025 | CVSS5.9v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-25420HIGH | Ignite Realtime Openfire privilege escalation vulnerabilityAn issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component. | CVSS7.2v3.1 | EPSS1.43% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-32315HIGH | Openfire administration console authentication bypassOpenfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire th… | CVSS8.6v3.1 | EPSS>99.9% | PoCs13 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |