Medium severity6.1NVD Advisory· Published Jan 8, 2020· Updated Jun 17, 2026
CVE-2019-20366
CVE-2019-20366
Description
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.igniterealtime.openfire:parentMaven | < 4.5.0 | 4.5.0 |
Affected products
3- cpe:2.3:a:igniterealtime:openfire:4.4.4:*:*:*:*:*:*:*
- Ignite Realtime/Openfiredescription
Patches
Vulnerability mechanics
References
6- cybersecurityworks.com/zerodays/cve-2019-20366-openfire.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-m6pr-xcrm-4qqpghsaADVISORY
- github.com/igniterealtime/Openfire/pull/1561nvdThird Party AdvisoryWEB
- issues.igniterealtime.org/browse/OF-1955nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-20366ghsaADVISORY
- github.com/igniterealtime/Openfire/commit/fef55d4be50da8f66f468d9e7d822528acb8273dghsaWEB
News mentions
0No linked articles in our index yet.