Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openfire CRITICAL 9.8
CVE-2024-25421

An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.

Fix: after 4.9.0
Fix from $2,300 2024-03-26
Openfire HIGH 7.2
CVE-2024-25420

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property compon…

Fix: after 4.9.0
Fix from $1,950 2024-03-26
Openfire HIGH 7.5
CVE-2023-32315 KEVEPSS 100%

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be…

Fix: 4.6.8 / 4.7.5+
Fix from $1,950 2023-05-26
Openfire MEDIUM 6.1
CVE-2020-35200

Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35201

Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35202

Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35199

Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.

No fix yet
Fix from $1,600 2020-12-12
Openfire MEDIUM 5.4
CVE-2020-35127

Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.

No fix yet
Fix from $1,600 2020-12-11
Openfire MEDIUM 6.1
CVE-2020-24601

In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST …

No fix yet
Fix from $1,600 2020-09-02
Openfire MEDIUM 6.1
CVE-2020-24602

Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the…

No fix yet
Fix from $1,600 2020-09-02
Openfire MEDIUM 6.1
CVE-2020-24604

A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbit…

No fix yet
Fix from $1,600 2020-09-02
Spark HIGH 8.8
CVE-2020-12772

An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC …

No fix yet
Fix from $1,950 2020-05-12
Openfire MEDIUM 6.1
CVE-2019-20525

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.

No fix yet
Fix from $1,600 2020-03-19
Openfire MEDIUM 6.1
CVE-2019-20526

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.

No fix yet
Fix from $1,600 2020-03-19
Openfire MEDIUM 6.1
CVE-2019-20527

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.

No fix yet
Fix from $1,600 2020-03-19
Openfire MEDIUM 6.1
CVE-2019-20528

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.

No fix yet
Fix from $1,600 2020-03-18
Openfire MEDIUM 6.1
CVE-2019-20363

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.

Patch available
Fix from $1,600 2020-01-08
Openfire MEDIUM 6.1
CVE-2019-20364

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.

Patch available
Fix from $1,600 2020-01-08
Openfire MEDIUM 6.1
CVE-2019-20365

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.

Patch available
Fix from $1,600 2020-01-08
Openfire MEDIUM 6.1
CVE-2019-20366

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.

Patch available
Fix from $1,600 2020-01-08
Openfire CRITICAL 9.8
CVE-2019-18394EPSS 32%

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrar…

Fix: after 4.4.2
Fix from $2,300 2019-10-24
Openfire MEDIUM 5.3
CVE-2019-18393EPSS 14%

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka …

Fix: after 4.4.2
Fix from $1,600 2019-10-24
Openfire MEDIUM 6.1
CVE-2019-15488

Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.

Fix: 4.4.1+
Fix from $1,600 2019-08-23
Openfire MEDIUM 6.1
CVE-2018-11688

Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker …

Patch available
Fix from $1,600 2018-06-13
User Import Export HIGH 8.1
CVE-2017-2815

An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the r…

Mitigation only
Fix from $1,950 2018-05-15
Openfire HIGH 7.5
CVE-2014-3451

OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.

Fix: after 3.9.3
Fix from $1,950 2017-08-18
Openfire MEDIUM 6.5
CVE-2015-7707EPSS 6%

Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.

No fix yet
Fix from $1,600 2015-10-05
Openfire MEDIUM 6.8
CVE-2015-6973EPSS 65%

Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of …

No fix yet
Fix from $1,600 2015-09-16
Smack MEDIUM 5.8
CVE-2014-0363

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509…

Fix: 4.0.0+
Fix from $1,600 2014-04-30
Smack MEDIUM 5.0
CVE-2014-0364EPSS 6%

The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, whic…

Fix: 4.0.0+
Fix from $1,600 2014-04-30