← Back

Igniterealtime

igniterealtime

43 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Openfire
openfire
Smack
smack
Smack Api
smack_api
Spark
spark

CVEs (43)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Igniterealtime
1Openfire
Apr 23, 2026
Mar 23, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.
1Igniterealtime
1Openfire
Apr 23, 2026
Mar 23, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI th...Show more
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/.. sequence in a URI.Show less
1Igniterealtime
1Openfire
Apr 23, 2026
Feb 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter.