← Back

Open Xchange Appsuite

open-xchange_appsuite

Vendor: Open Xchange • 157 CVEs

CVEs (157)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jan 6, 2020
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
OX App Suite through 7.10.2 has Incorrect Access Control.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of a...Show more
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publicati...Show more
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subje...Show more
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the body of the email and the publication name were SPLIT from this CVE ID because they affect different sets of versions.Show less
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Oct 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite 7.10.1 and 7.10.2 allows XSS.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Oct 14, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
OX App Suite through 7.10.2 has Insecure Permissions.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Oct 14, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 20, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
OX App Suite 7.10.1 and earlier has Insecure Permissions.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX App Suite 7.10.0 to 7.10.2 allows XSS.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 20, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
OX App Suite 7.10.1 allows Content Spoofing.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jun 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OX App Suite 7.10.1 and earlier allows Information Exposure.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jun 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.