Vendor CVEs
Open-Xchange
All CVEs
304 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44208 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. | ||
| CVE-2021-38377 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results. | ||
| CVE-2021-38375 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message. | ||
| CVE-2021-33495 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite 7.10.5 allows XSS via an OX Chat system message. | ||
| CVE-2021-33494 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering. | ||
| CVE-2021-33492 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite 7.10.5 allows XSS via an OX Chat room name. | ||
| CVE-2021-33490 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. | ||
| CVE-2021-33489 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. | ||
| CVE-2021-33488 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook. | ||
| CVE-2021-37403 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used. | ||
| CVE-2021-37402 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled. | ||
| CVE-2021-26698 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and the dl parameter is used. | ||
| CVE-2020-28945 | Med | 0.40 | 6.1 | 0.01 | May 3, 2021 | OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as  that is mishandled in the scheduling view. | ||
| CVE-2021-31934 | Med | 0.40 | 6.1 | 0.01 | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone. | ||
| CVE-2021-23936 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via the subject of a task. | ||
| CVE-2021-23935 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code. | ||
| CVE-2021-23934 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code. | ||
| CVE-2021-23933 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL. | ||
| CVE-2021-23932 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename. | ||
| CVE-2021-23931 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline binary file. | ||
| CVE-2021-23930 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile. | ||
| CVE-2021-23929 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI. | ||
| CVE-2021-23928 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string. | ||
| CVE-2020-24701 | Med | 0.40 | 6.1 | 0.07 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI). | ||
| CVE-2020-9426 | Med | 0.40 | 6.1 | 0.01 | Jun 15, 2020 | OX Guard 2.10.3 and earlier allows XSS. | ||
| CVE-2019-16717 | Med | 0.40 | 6.1 | 0.02 | Jan 6, 2020 | OX App Suite through 7.10.2 has XSS. | ||
| CVE-2013-7486 | Med | 0.40 | 6.1 | 0.02 | Jan 2, 2020 | Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from… | ||
| CVE-2013-7485 | Med | 0.40 | 6.1 | 0.02 | Jan 2, 2020 | Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message.… | ||
| CVE-2013-6242 | Med | 0.40 | 6.1 | 0.02 | Jan 2, 2020 | Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the… | ||
| CVE-2019-14227 | Med | 0.40 | 6.1 | 0.01 | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows XSS. | ||
| CVE-2017-5213 | Med | 0.40 | 6.1 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-15030 | Med | 0.40 | 6.1 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-9808 | Med | 0.40 | 6.1 | 0.01 | May 22, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-5864 | Med | 0.40 | 6.1 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2017-12885 | Med | 0.40 | 6.1 | 0.01 | May 10, 2019 | OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). | ||
| CVE-2018-12611 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Directory Traversal. | ||
| CVE-2017-6913 | Med | 0.40 | 6.1 | 0.01 | Sep 18, 2018 | Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag. | ||
| CVE-2018-9997 | Med | 0.40 | 6.1 | 0.02 | Jul 5, 2018 | Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute… | ||
| CVE-2015-1588 | Med | 0.40 | 6.1 | 0.02 | Jun 8, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21. | ||
| CVE-2016-6846 | Med | 0.40 | 6.1 | 0.01 | Mar 29, 2017 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0… | ||
| CVE-2016-6850 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as profile pictures. In case their XML structure contains iframes and script code, that code may get executed when calling the related picture URL or viewing the related person's image… | ||
| CVE-2016-6847 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cover URL. Malicious script code can be executed within a… | ||
| CVE-2016-6845 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded "data" resources. This allows an attacker to provide hyperlinks that may execute script code instead… | ||
| CVE-2016-6844 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within SVG files is maintained when opening such files "in browser" based on our Mail or Drive app. In case of "a" tags, this may include link targets with base64 encoded "data" references.… | ||
| CVE-2016-6843 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which creates or changes the group by using autocomplete. In most… | ||
| CVE-2016-6842 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user's name to JS code makes that code execute when selecting that user's "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code… | ||
| CVE-2016-5124 | Med | 0.40 | 6.1 | 0.02 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. To exploit this, a user needs to be tricked to use an image… | ||
| CVE-2016-4045 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script… | ||
| CVE-2016-4026 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The content sanitizer component has an issue with filtering malicious content in case invalid HTML code is provided. In such cases the filter will output a unsanitized representation of the content.… |
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.5 allows XSS via an OX Chat room name.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
- risk 0.40cvss 6.1epss 0.01
chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and the dl parameter is used.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as  that is mishandled in the scheduling view.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via the subject of a task.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an inline binary file.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
- risk 0.40cvss 6.1epss 0.07
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
- risk 0.40cvss 6.1epss 0.01
OX Guard 2.10.3 and earlier allows XSS.
- risk 0.40cvss 6.1epss 0.02
OX App Suite through 7.10.2 has XSS.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from…
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message.…
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the…
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.1 and 7.10.2 allows XSS.
- risk 0.40cvss 6.1epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.8.4 and earlier allows Directory Traversal.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute…
- risk 0.40cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as profile pictures. In case their XML structure contains iframes and script code, that code may get executed when calling the related picture URL or viewing the related person's image…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. SVG files can be used as mp3 album covers. In case their XML structure contains script code, that code may get executed when calling the related cover URL. Malicious script code can be executed within a…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded "data" resources. This allows an attacker to provide hyperlinks that may execute script code instead…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code within SVG files is maintained when opening such files "in browser" based on our Mail or Drive app. In case of "a" tags, this may include link targets with base64 encoded "data" references.…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Script code can be injected to contact names. When adding those contacts to a group, the script code gets executed in the context of the user which creates or changes the group by using autocomplete. In most…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Setting the user's name to JS code makes that code execute when selecting that user's "Templates" folder from OX Documents settings. This requires the folder to be shared to the victim. Malicious script code…
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev14. Adding images from external sources to HTML editors by drag&drop can potentially lead to script code execution in the context of the active user. To exploit this, a user needs to be tricked to use an image…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Script code can be embedded to RSS feeds using a URL notation. In case a user clicks the corresponding link at the RSS reader of App Suite, code gets executed at the context of the user. Malicious script…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The content sanitizer component has an issue with filtering malicious content in case invalid HTML code is provided. In such cases the filter will output a unsanitized representation of the content.…
Page 3 of 7