Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-25421 An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component. Openfire after 4.9.0 Fix from $2,3002024-03-26 HIGH 7.2 CVE-2024-25420 An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property compon… Openfire after 4.9.0 Fix from $1,9502024-03-26 HIGH 7.5 CVE-2023-32315 KEVEPSS 100% Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be… Openfire 4.6.8 / 4.7.5+ Fix from $1,9502023-05-26 MEDIUM 6.1 CVE-2020-35200 Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35201 Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35202 Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35199 Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35127 Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS. Openfire No fix yet Fix from $1,6002020-12-11 MEDIUM 6.1 CVE-2020-24601 In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST … Openfire No fix yet Fix from $1,6002020-09-02 MEDIUM 6.1 CVE-2020-24602 Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the… Openfire No fix yet Fix from $1,6002020-09-02 MEDIUM 6.1 CVE-2020-24604 A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbit… Openfire No fix yet Fix from $1,6002020-09-02 HIGH 8.8 CVE-2020-12772 An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC … Spark No fix yet Fix from $1,9502020-05-12 MEDIUM 6.1 CVE-2019-20525 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter. Openfire No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20526 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter. Openfire No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20527 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. Openfire No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20528 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. Openfire No fix yet Fix from $1,6002020-03-18 MEDIUM 6.1 CVE-2019-20363 An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents. Openfire Patch available Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-20364 An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. Openfire Patch available Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-20365 An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. Openfire Patch available Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-20366 An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents. Openfire Patch available Fix from $1,6002020-01-08 CRITICAL 9.8 CVE-2019-18394EPSS 32% A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrar… Openfire after 4.4.2 Fix from $2,3002019-10-24 MEDIUM 5.3 CVE-2019-18393EPSS 14% PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka … Openfire after 4.4.2 Fix from $1,6002019-10-24 MEDIUM 6.1 CVE-2019-15488 Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. Openfire 4.4.1+ Fix from $1,6002019-08-23 MEDIUM 6.1 CVE-2018-11688 Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker … Openfire Patch available Fix from $1,6002018-06-13 HIGH 8.1 CVE-2017-2815 An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the r… User Import Export Mitigation only Fix from $1,9502018-05-15 HIGH 7.5 CVE-2014-3451 OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks. Openfire after 3.9.3 Fix from $1,9502017-08-18 MEDIUM 6.5 CVE-2015-7707EPSS 6% Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. Openfire No fix yet Fix from $1,6002015-10-05 MEDIUM 6.8 CVE-2015-6973EPSS 65% Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of … Openfire No fix yet Fix from $1,6002015-09-16 MEDIUM 5.8 CVE-2014-0363 The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509… Smack 4.0.0+ Fix from $1,6002014-04-30 MEDIUM 5.0 CVE-2014-0364EPSS 6% The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, whic… Smack 4.0.0+ Fix from $1,6002014-04-30