open-xchange

272 tracked vulnerabilities.

CVE-2023-41703 MEDIUM
open-xchange_appsuite < 7.10.6 - Stored Cross-Site Scripting via Document Comment Mentions
Feb 12, 2024
CVSS 6.1
EPSS 0.01
CVE-2023-41710 MEDIUM
OX App Suite < 7.10.6 - Stored Cross-Site Scripting via Upsell Shop URL
Jan 08, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-29052 MEDIUM
OX App Suite - Stored Cross-Site Scripting via Disclaimer Text
Jan 08, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-29051 HIGH
OX App Suite < 7.10.6 - Unauthenticated Improper Access Control via User-Defined OXMF Templates
Jan 08, 2024
CVSS 8.1
EPSS 0.00
CVE-2023-29050 HIGH
LDAP contacts provider - Info Disclosure
Jan 08, 2024
CVSS 7.6
EPSS 0.00
CVE-2023-29049 MEDIUM
OX App Suite < 7.10.6 - Stored Cross-Site Scripting via Upsell Widget
Jan 08, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-29048 HIGH
OXMF Template Engine - Command Injection
Jan 08, 2024
CVSS 8.8
EPSS 0.00
CVE-2023-29047 MEDIUM
Open-Xchange AppSuite < 7.10.6 - SQL Injection via Imageconverter API
Nov 02, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-29046 MEDIUM
Open-Xchange AppSuite - Resource Exhaustion via External Connections
Nov 02, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-29045 MEDIUM
Open-Xchange AppSuite - Code Injection in Document Drawing Operations
Nov 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-29044 MEDIUM
open-xchange_appsuite < 7.10.6 - Stored Cross-Site Scripting via Document Collaboration
Nov 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-29043 MEDIUM
Open-Xchange AppSuite - Cross-Site Scripting via Image References
Nov 02, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-26456 MEDIUM
OX Guard < 2.10.7 - Stored Cross-Site Scripting via Product Name
Nov 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26455 MEDIUM
Open-Xchange App Suite ChronosRMIService - Unauthenticated Calendar Modification
Nov 02, 2023
CVSS 5.6
EPSS 0.00
CVE-2023-26454 HIGH
open-xchange_appsuite < 7.10.6 - SQL Injection via Image Metadata Fetch Request
Nov 02, 2023
CVSS 7.6
EPSS 0.00
CVE-2023-26453 HIGH
Open-Xchange AppSuite < 7.10.6 - SQL Injection via Image Cache Request
Nov 02, 2023
CVSS 7.6
EPSS 0.00
CVE-2023-26452 HIGH
open-xchange_appsuite < 7.10.6 - SQL Injection via Image Metadata Caching
Nov 02, 2023
CVSS 7.6
EPSS 0.00
CVE-2023-26451 HIGH
OAuth Authorization Service - Info Disclosure
Aug 02, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-26450 MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Cross-Site Scripting via OX Count Web Service
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26449 MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Cross-Site Scripting via OX Chat Response Media-Type
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26448 MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Stored Cross-Site Scripting via Custom Log-in/Log-out Locations
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26447 MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Stored Cross-Site Scripting in Upsell Widget
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26446 MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Stored Cross-Site Scripting via ClientID Parameter
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26445 MEDIUM
Open-Xchange App Suite jslob Theme - Cross-Site Scripting
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26443 MEDIUM
Full-text autocomplete search - SQL Injection
Aug 02, 2023
CVSS 5.5
EPSS 0.00