CVEs (157)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Jan 26, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified oAuth API functions. |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Jan 26, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to crafted "<%" tags. |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Jan 26, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 XML External Entity (XXE) vulnerability in the CalDAV interface in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote authenticated users to read portions of arbitrary files via vectors related to the SAX builder...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wil...Show more |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Nov 20, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14 allows remote attackers to inject arbitrary web script or HTML via an attached SVG file. |
CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite before 7.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) content with the text/xml MIME type or (2) the Sta...Show more |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Sep 25, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 allows remote attackers to obtain sensitive information about (1) runtime activity, (2) network configuration, (3)...Show more |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Sep 25, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remo...Show more |
1Open Xchange 1Open Xchange Appsuite Apr 29, 2026 Sep 25, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 has a hardcoded password for node join operations, which allows remote attackers to expand a cluster by finding this password in the source code...Show more |
The (1) REST and (2) memcache interfaces in the Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 do not require authentication, which allows remote attackers to obtain...Show more |
1Open Xchange 2Open Xchange Appsuite Open Xchange ServerApr 29, 2026 Sep 5, 2013 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inj...Show more |
2Htmlcleaner Project Open Xchange2Htmlcleaner Open Xchange AppsuiteApr 29, 2026 Sep 5, 2013 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic ci...Show more |
Open-Xchange AppSuite before 7.0.2 rev14, 7.2.0 before rev11, 7.2.1 before rev10, and 7.2.2 before rev9 relies on user-supplied data to predict the IMAP server hostname for an external domain name, which allows remote au...Show more |
1Open Xchange 2Open Xchange Appsuite Open Xchange ServerApr 29, 2026 Sep 5, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev18, 6.22.0 before rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allow re...Show more |
1Open Xchange 2Open Xchange Appsuite Open Xchange ServerApr 29, 2026 Sep 5, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev16, 6.22.0 before rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allow remote attackers to in...Show more |
1Open Xchange 2Open Xchange Appsuite Open Xchange ServerApr 29, 2026 Sep 5, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP...Show more |