Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Alfresco MEDIUM 6.1
CVE-2020-18327

Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-…

No fix yet
Fix from $1,600 2022-03-04
Alfresco Content Services HIGH 8.8
CVE-2021-41790

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded o…

Fix: after 7.0.1.2
Fix from $1,950 2021-10-21
Community Share MEDIUM 5.4
CVE-2021-41791

An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for H…

Fix: after 7.0
Fix from $1,600 2021-10-21
Alfresco Content Services MEDIUM 5.3
CVE-2021-41792

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A…

Fix: after 6.2.2.18
Fix from $1,600 2021-10-21
Reset Password CRITICAL 9.8
CVE-2020-15181

The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the sy…

Fix: 1.2.0+
Fix from $2,300 2020-09-18
Reset Password HIGH 8.8
CVE-2020-25728

The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's…

Fix: 1.2.0+
Fix from $1,950 2020-09-17
Alfresco MEDIUM 5.4
CVE-2020-8776

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.

Fix: 5.2.7 / 6.2.0+
Fix from $1,600 2020-03-02
Alfresco MEDIUM 5.4
CVE-2020-8777

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT e…

Fix: 5.2.7 / 6.2.0+
Fix from $1,600 2020-03-02
Alfresco MEDIUM 5.4
CVE-2020-8778

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write a…

Fix: 5.2.7 / 6.2.0+
Fix from $1,600 2020-03-02
Alfresco MEDIUM 5.4
CVE-2019-19496

Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.

Fix: 5.2.5+
Fix from $1,600 2019-12-02
Alfresco MEDIUM 6.1
CVE-2019-14223

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open …

Fix: 5.2.6+
Fix from $1,600 2019-09-06
Alfresco CRITICAL 9.8
CVE-2019-14222

An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's So…

Fix: after 6.0
Fix from $2,300 2019-09-05
Alfresco HIGH 7.2
CVE-2019-14224EPSS 5%

An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit…

No fix yet
Fix from $1,950 2019-09-05
Alfresco CRITICAL 9.8
CVE-2019-15566

The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.

Fix: 1.8.7+
Fix from $2,300 2019-08-26
Alfresco MEDIUM 5.8
CVE-2015-3366

Cross-site request forgery (CSRF) vulnerability in the Alfresco module before 6.x-1.3 for Drupal allows remote attackers to hijack the authentication…

Fix: after 6.x-1.2
Fix from $1,600 2015-04-21
Community Edition MEDIUM 5.0
CVE-2014-9302

Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communi…

Fix: after 5.0.a
Fix from $1,600 2014-12-07
Alfresco MEDIUM 6.4
CVE-2014-9301

Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger o…

Fix: after 4.2.f
Fix from $1,600 2014-12-07
Alfresco MEDIUM 6.8
CVE-2014-9300

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communit…

Fix: after 5.0.a
Fix from $1,600 2014-12-07