Alfresco Enterprise Repo
by Alfresco
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8778 | Med | 0.38 | 5.4 | 0.03 | Mar 2, 2020 | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project. | ||
| CVE-2020-8777 | Med | 0.38 | 5.4 | 0.03 | Mar 2, 2020 | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document. | ||
| CVE-2020-8776 | Med | 0.38 | 5.4 | 0.03 | Mar 2, 2020 | Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file. | ||
| CVE-2019-19496 | Med | 0.35 | 5.4 | 0.01 | Dec 2, 2019 | Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document. | ||
| CVE-2025-0557 | Med | 0.28 | 4.3 | 0.01 | Jan 18, 2025 | A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is… |
- risk 0.38cvss 5.4epss 0.03
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
- risk 0.38cvss 5.4epss 0.03
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
- risk 0.38cvss 5.4epss 0.03
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.
- risk 0.35cvss 5.4epss 0.01
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
- risk 0.28cvss 4.3epss 0.01
A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is…