← Back

Citadel

citadel

Vendor: Citadel • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citadel
1Citadel
Jun 17, 2026
Oct 4, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.
1Citadel
1Citadel
Apr 29, 2026
Jun 21, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML d...Show more
modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.Show less