VYPR

Vendor CVEs

Open-Xchange

All CVEs

304 total · sorted by risk
  • CVE-2021-44208MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.

  • CVE-2021-38377MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.

  • CVE-2021-38375MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.

  • CVE-2021-33495MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.5 allows XSS via an OX Chat system message.

  • CVE-2021-33494MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.

  • CVE-2021-33492MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.5 allows XSS via an OX Chat room name.

  • CVE-2021-33490MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

  • CVE-2021-33489MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.

  • CVE-2021-33488MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

  • CVE-2021-37403MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.

  • CVE-2021-37402MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.

  • CVE-2021-26698MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and the dl parameter is used.

  • CVE-2020-28945MedMay 3, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in a Notes item.

  • CVE-2021-31935MedApr 30, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandled in the scheduling view.

  • CVE-2021-31934MedApr 30, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.

  • CVE-2021-23936MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via the subject of a task.

  • CVE-2021-23935MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.

  • CVE-2021-23934MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.

  • CVE-2021-23933MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.

  • CVE-2021-23932MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.

  • CVE-2021-23931MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via an inline binary file.

  • CVE-2021-23930MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.

  • CVE-2021-23929MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI.

  • CVE-2021-23928MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.01

    OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.

  • CVE-2020-24701MedJan 12, 2021
    risk 0.40cvss 6.1epss 0.07

    OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).

  • CVE-2020-9426MedJun 15, 2020
    risk 0.40cvss 6.1epss 0.01

    OX Guard 2.10.3 and earlier allows XSS.

  • CVE-2019-16717MedJan 6, 2020
    risk 0.40cvss 6.1epss 0.02

    OX App Suite through 7.10.2 has XSS.

  • CVE-2013-7486MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from…

  • CVE-2013-7485MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message.…

  • CVE-2013-6242MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the…

  • CVE-2019-14227MedOct 14, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.10.1 and 7.10.2 allows XSS.

  • CVE-2017-5213MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-15030MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-9808MedMay 22, 2019
    risk 0.40cvss 6.1epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-5864MedMay 22, 2019
    risk 0.40cvss 6.1epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-12885MedMay 10, 2019
    risk 0.40cvss 6.1epss 0.01

    OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2018-12611MedJan 30, 2019
    risk 0.40cvss 6.1epss 0.01

    OX App Suite 7.8.4 and earlier allows Directory Traversal.

  • CVE-2017-6913MedSep 18, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.

  • CVE-2018-9997MedJul 5, 2018
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute…

  • CVE-2015-1588MedJun 8, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.

  • CVE-2016-6846MedMar 29, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0…

  • CVE-2016-6850MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as profile pictures. In case their XML structure contains iframes and script code, that code may get executed when calling the related picture URL or viewing the related person's image…

  • CVE-2016-6847MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cover URL. Malicious script code can be executed within a…

  • CVE-2016-6845MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded "data" resources. This allows an attacker to provide hyperlinks that may execute script code instead…

  • CVE-2016-6844MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within SVG files is maintained when opening such files "in browser" based on our Mail or Drive app. In case of "a" tags, this may include link targets with base64 encoded "data" references.…

  • CVE-2016-6843MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which creates or changes the group by using autocomplete. In most…

  • CVE-2016-6842MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user's name to JS code makes that code execute when selecting that user's "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code…

  • CVE-2016-5124MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. To exploit this, a user needs to be tricked to use an image…

  • CVE-2016-4045MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script…

  • CVE-2016-4026MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The content sanitizer component has an issue with filtering malicious content in case invalid HTML code is provided. In such cases the filter will output a unsanitized representation of the content.…

Page 3 of 7