open-xchange

272 tracked vulnerabilities.

CVE-2022-43699 MEDIUM
OX App Suite < 7.10.6-rev30 - Server-Side Request Forgery via Email Account Discovery
Apr 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2022-43698 MEDIUM
OX App Suite < 7.10.6-rev30 - Server-Side Request Forgery via POP3 Account Configuration
Apr 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2022-43697 MEDIUM
OX App Suite < 7.10.6-rev30 - Cross-Site Scripting via Activity Tracking Adapter
Apr 15, 2023
CVSS 6.1
EPSS 0.00
CVE-2022-43696 MEDIUM
OX App Suite < 7.10.6-rev20 - Cross-Site Scripting via Upsell Ads
Apr 15, 2023
CVSS 6.1
EPSS 0.00
CVE-2022-37310 MEDIUM
Open-xchange Appsuite < 7.10.5 - XSS
Dec 26, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-37309 MEDIUM
Open-xchange Appsuite < 7.10.5 - XSS
Dec 26, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-29853 MEDIUM
Open-xchange Appsuite < 7.10.5 - XSS
Dec 26, 2022
CVSS 5.4
EPSS 0.01
CVE-2022-29852 MEDIUM
Open-xchange Appsuite < 7.10.5 - XSS
Dec 26, 2022
CVSS 5.4
EPSS 0.01
CVE-2022-37308 MEDIUM
Open-xchange Appsuite < 7.10.5 - XSS
Dec 26, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-37313 MEDIUM
Open-xchange Appsuite < 7.10.5 - SSRF
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-37312 MEDIUM
OX App Suite <7.10.6 - DoS
Dec 26, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-37311 MEDIUM
OX App Suite <7.10.6 - DoS
Dec 26, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-37307 MEDIUM
Open-xchange Appsuite < 7.10.5 - XSS
Dec 26, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-31469 MEDIUM
OX App Suite <7.10.6 - XSS
Dec 26, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-31468 MEDIUM
OX App Suite < 8.2 - Cross-Site Scripting via Attachment or OX Drive Content
Oct 25, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-29851 CRITICAL
OX App Suite < 7.10.6 - OS Command Injection via EPS Document Disguised as PDF
Oct 25, 2022
CVSS 9.8
EPSS 0.02
CVE-2022-24406 MEDIUM
OX App Suite <= 7.10.6 - Server-Side Request Forgery via Predictable Multipart Boundary
Jul 27, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-24405 CRITICAL
OX App Suite <7.10.6 - Code Injection
Jul 27, 2022
CVSS 9.8
EPSS 0.08
CVE-2022-23101 MEDIUM
OX App Suite <= 7.10.6 - Cross-Site Scripting via Deep Link in Email Message
Jul 27, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-23100 CRITICAL
OX App Suite <= 7.10.6 - OS Command Injection via Documentconverter
Jul 27, 2022
CVSS 9.8
EPSS 0.03
CVE-2022-23099 MEDIUM
OX App Suite < 7.10.6 - Cross-Site Scripting via Block-Wise Read
Jul 27, 2022
CVSS 5.4
EPSS 0.01
CVE-2021-44213 MEDIUM
OX App Suite <= 7.10.5 - Cross-Site Scripting via UUEncoded Multipart Message
Mar 28, 2022
CVSS 6.1
EPSS 0.00
CVE-2021-44212 MEDIUM
OX App Suite <= 7.10.5 - Cross-Site Scripting via Trailing Control Character
Mar 28, 2022
CVSS 6.1
EPSS 0.00
CVE-2021-44211 MEDIUM
OX App Suite <= 7.10.5 - Cross-Site Scripting via HTML Email Signature Class Attribute
Mar 28, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-44210 MEDIUM
OX App Suite <= 7.10.5 - Cross-Site Scripting via NIFF Data
Mar 28, 2022
CVSS 6.1
EPSS 0.00