Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-71276 SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories. Sogo 5.12.5+ Fix from $1,6002026-03-22 MEDIUM 6.1 CVE-2026-3054 A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross s… Sogo Mitigation only Fix from $1,6002026-02-24 MEDIUM 6.1 CVE-2025-63499 Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter. Sogo after 5.12.4 Fix from $1,6002025-12-04 MEDIUM 6.1 CVE-2024-24510 Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mai… Sogo 5.10.0+ Fix from $1,6002024-09-09 MEDIUM 6.1 CVE-2024-34462 Alinto SOGo through 5.10.0 allows XSS during attachment preview. Sogo 5.11.0+ Fix from $1,6002024-05-04 MEDIUM 6.1 CVE-2023-48104 Alinto SOGo before 5.9.1 is vulnerable to HTML Injection. Sogo 5.9.1+ Fix from $1,6002024-01-16 MEDIUM 6.1 CVE-2020-22402 Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an ema… Sogo Web Mail 4.3.1+ Fix from $1,6002023-06-14 MEDIUM 6.1 CVE-2022-4556 A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of … Sogo 5.8.0+ Fix from $1,6002022-12-16 MEDIUM 6.1 CVE-2022-4558 A vulnerability was found in Alinto SOGo up to 5.7.1. It has been classified as problematic. This affects an unknown part of the file SoObjects/SOGo/… Sogo 5.8.0+ Fix from $1,6002022-12-16 MEDIUM 6.1 CVE-2014-9905 Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or… Sogo after 2.1.1 Fix from $1,6002017-02-17 MEDIUM 6.1 CVE-2016-6191 Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to in… Sogo after 3.1.2 Fix from $1,6002017-02-17 MEDIUM 6.5 CVE-2016-6188 Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large … Sogo Patch available Fix from $1,6002017-02-03