open-xchange
272 tracked vulnerabilities.
CVE-2023-41703
MEDIUM
open-xchange_appsuite < 7.10.6 - Stored Cross-Site Scripting via Document Comment Mentions
Feb 12, 2024
CVSS 6.1
EPSS 0.01
CVE-2023-41710
MEDIUM
OX App Suite < 7.10.6 - Stored Cross-Site Scripting via Upsell Shop URL
Jan 08, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-29052
MEDIUM
OX App Suite - Stored Cross-Site Scripting via Disclaimer Text
Jan 08, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-29051
HIGH
OX App Suite < 7.10.6 - Unauthenticated Improper Access Control via User-Defined OXMF Templates
Jan 08, 2024
CVSS 8.1
EPSS 0.00
CVE-2023-29050
HIGH
LDAP contacts provider - Info Disclosure
Jan 08, 2024
CVSS 7.6
EPSS 0.00
CVE-2023-29049
MEDIUM
OX App Suite < 7.10.6 - Stored Cross-Site Scripting via Upsell Widget
Jan 08, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-29048
HIGH
OXMF Template Engine - Command Injection
Jan 08, 2024
CVSS 8.8
EPSS 0.00
CVE-2023-29047
MEDIUM
Open-Xchange AppSuite < 7.10.6 - SQL Injection via Imageconverter API
Nov 02, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-29046
MEDIUM
Open-Xchange AppSuite - Resource Exhaustion via External Connections
Nov 02, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-29045
MEDIUM
Open-Xchange AppSuite - Code Injection in Document Drawing Operations
Nov 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-29044
MEDIUM
open-xchange_appsuite < 7.10.6 - Stored Cross-Site Scripting via Document Collaboration
Nov 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-29043
MEDIUM
Open-Xchange AppSuite - Cross-Site Scripting via Image References
Nov 02, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-26456
MEDIUM
OX Guard < 2.10.7 - Stored Cross-Site Scripting via Product Name
Nov 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26455
MEDIUM
Open-Xchange App Suite ChronosRMIService - Unauthenticated Calendar Modification
Nov 02, 2023
CVSS 5.6
EPSS 0.00
CVE-2023-26454
HIGH
open-xchange_appsuite < 7.10.6 - SQL Injection via Image Metadata Fetch Request
Nov 02, 2023
CVSS 7.6
EPSS 0.00
CVE-2023-26453
HIGH
Open-Xchange AppSuite < 7.10.6 - SQL Injection via Image Cache Request
Nov 02, 2023
CVSS 7.6
EPSS 0.00
CVE-2023-26452
HIGH
open-xchange_appsuite < 7.10.6 - SQL Injection via Image Metadata Caching
Nov 02, 2023
CVSS 7.6
EPSS 0.00
CVE-2023-26451
HIGH
OAuth Authorization Service - Info Disclosure
Aug 02, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-26450
MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Cross-Site Scripting via OX Count Web Service
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26449
MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Cross-Site Scripting via OX Chat Response Media-Type
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26448
MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Stored Cross-Site Scripting via Custom Log-in/Log-out Locations
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26447
MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Stored Cross-Site Scripting in Upsell Widget
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26446
MEDIUM
open-xchange_appsuite_frontend < 7.10.6 - Stored Cross-Site Scripting via ClientID Parameter
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26445
MEDIUM
Open-Xchange App Suite jslob Theme - Cross-Site Scripting
Aug 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26443
MEDIUM
Full-text autocomplete search - SQL Injection
Aug 02, 2023
CVSS 5.5
EPSS 0.00
Products
Quick Filters