Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sogo MEDIUM 6.1
CVE-2025-71276

SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

Fix: 5.12.5+
Fix from $1,600 2026-03-22
Sogo MEDIUM 6.1
CVE-2026-3054

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross s…

Mitigation only
Fix from $1,600 2026-02-24
Sogo MEDIUM 6.1
CVE-2025-63499

Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

Fix: after 5.12.4
Fix from $1,600 2025-12-04
Sogo MEDIUM 6.1
CVE-2024-24510

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mai…

Fix: 5.10.0+
Fix from $1,600 2024-09-09
Sogo MEDIUM 6.1
CVE-2024-34462

Alinto SOGo through 5.10.0 allows XSS during attachment preview.

Fix: 5.11.0+
Fix from $1,600 2024-05-04
Sogo MEDIUM 6.1
CVE-2023-48104

Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

Fix: 5.9.1+
Fix from $1,600 2024-01-16
Sogo Web Mail MEDIUM 6.1
CVE-2020-22402

Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an ema…

Fix: 4.3.1+
Fix from $1,600 2023-06-14
Sogo MEDIUM 6.1
CVE-2022-4556

A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of …

Fix: 5.8.0+
Fix from $1,600 2022-12-16
Sogo MEDIUM 6.1
CVE-2022-4558

A vulnerability was found in Alinto SOGo up to 5.7.1. It has been classified as problematic. This affects an unknown part of the file SoObjects/SOGo/…

Fix: 5.8.0+
Fix from $1,600 2022-12-16
Sogo MEDIUM 6.1
CVE-2014-9905

Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or…

Fix: after 2.1.1
Fix from $1,600 2017-02-17
Sogo MEDIUM 6.1
CVE-2016-6191

Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to in…

Fix: after 3.1.2
Fix from $1,600 2017-02-17
Sogo MEDIUM 6.5
CVE-2016-6188

Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large …

Patch available
Fix from $1,600 2017-02-03