Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Openfire MEDIUM 6.1
CVE-2020-35200

Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35201

Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35202

Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35199

Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35127

Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.

No fix yet
Fix from $1,600 2020-12-11
Openfire MEDIUM 6.1
CVE-2020-24601

In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST …

No fix yet
Fix from $1,600 2020-09-02
Openfire MEDIUM 6.1
CVE-2020-24602

Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the…

No fix yet
Fix from $1,600 2020-09-02
Openfire MEDIUM 6.1
CVE-2020-24604

A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbit…

No fix yet
Fix from $1,600 2020-09-02
Spark HIGH 8.8
CVE-2020-12772

An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC …

No fix yet
Fix from $1,950 2020-05-12
Openfire MEDIUM 6.1
CVE-2019-20525

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.

No fix yet
Fix from $1,600 2020-03-19
Openfire MEDIUM 6.1
CVE-2019-20526

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.

No fix yet
Fix from $1,600 2020-03-19
Openfire MEDIUM 6.1
CVE-2019-20527

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.

No fix yet
Fix from $1,600 2020-03-19
Openfire MEDIUM 6.1
CVE-2019-20528

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.

No fix yet
Fix from $1,600 2020-03-18
User Import Export HIGH 8.1
CVE-2017-2815

An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the r…

Mitigation only
Fix from $1,950 2018-05-15
Openfire MEDIUM 6.5
CVE-2015-7707EPSS 6%

Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.

No fix yet
Fix from $1,600 2015-10-05
Openfire MEDIUM 6.8
CVE-2015-6973EPSS 65%

Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of …

No fix yet
Fix from $1,600 2015-09-16
Openfire MEDIUM 5.0
CVE-2009-0497EPSS 8%

Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot bac…

No fix yet
Fix from $1,600 2009-02-10