VYPR

Vendor CVEs

Open-Xchange

All CVEs

304 total · sorted by risk
  • CVE-2016-2840MedDec 15, 2016
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted…

  • CVE-2021-33493MedNov 22, 2021
    risk 0.39cvss 6.0epss 0.00

    The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

  • CVE-2018-5755MedJun 16, 2018
    risk 0.39cvss 5.5epss 0.08

    Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to read arbitrary files via a full pathname in a formula in a…

  • CVE-2026-40205MedAug 28, 2026
    risk 0.38cvss 5.9epss 0.00

    An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation…

  • CVE-2018-5754MedJun 16, 2018
    risk 0.38cvss 5.4epss 0.03

    Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the…

  • CVE-2016-4046MedDec 15, 2016
    risk 0.38cvss 5.8epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. The API to configure external mail accounts can be abused to map and access network components within the trust boundary of the operator. Users can inject arbitrary hosts and ports to API calls. Depending…

  • CVE-2026-27855MedMar 27, 2026
    risk 0.37cvss 6.8epss 0.00

    Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as…

  • CVE-2023-26441MedAug 2, 2023
    risk 0.37cvss 5.7epss 0.00

    Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are…

  • CVE-2023-26455MedNov 2, 2023
    risk 0.36cvss 5.6epss 0.00

    RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated…

  • CVE-2023-26443MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.01

    Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly…

  • CVE-2016-6848MedDec 15, 2016
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windows) batch file can be created via a…

  • CVE-2025-59026MedNov 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch…

  • CVE-2025-30190MedNov 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch releases. No…

  • CVE-2025-30186MedNov 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Please deploy the provided updates and patch…

  • CVE-2025-30191MedOct 31, 2025
    risk 0.35cvss 5.4epss 0.00

    Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the…

  • CVE-2024-25582MedAug 19, 2024
    risk 0.35cvss 5.4epss 0.00

    Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform malicious API requests or extract information from the users account. Exploiting this vulnerability requires temporary access to an account or…

  • CVE-2024-23191MedApr 8, 2024
    risk 0.35cvss 5.4epss 0.01

    Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to…

  • CVE-2024-23190MedApr 8, 2024
    risk 0.35cvss 5.4epss 0.01

    Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously…

  • CVE-2024-23189MedApr 8, 2024
    risk 0.35cvss 5.4epss 0.01

    Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to the users account, access to another account within the same context or an successful…

  • CVE-2023-41708MedFeb 12, 2024
    risk 0.35cvss 5.4epss 0.00

    References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now…

  • CVE-2023-41710MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…

  • CVE-2023-29052MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added…

  • CVE-2023-29049MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.01

    The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a…

  • CVE-2023-29045MedNov 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged…

  • CVE-2023-29044MedNov 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating…

  • CVE-2023-26456MedNov 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to…

  • CVE-2023-26450MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…

  • CVE-2023-26449MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…

  • CVE-2023-26448MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface…

  • CVE-2023-26447MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking…

  • CVE-2023-26446MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit…

  • CVE-2023-26445MedAug 2, 2023
    risk 0.35cvss 5.4epss 0.01

    Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the…

  • CVE-2022-29853MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.00

    OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

  • CVE-2022-29852MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.00

    OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.

  • CVE-2022-37313MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

  • CVE-2022-37312MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.

  • CVE-2022-37311MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.

  • CVE-2022-23099MedJul 27, 2022
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.6 allows XSS by forcing block-wise read.

  • CVE-2021-44211MedMar 28, 2022
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.

  • CVE-2021-38376MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

  • CVE-2021-38374MedNov 22, 2021
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.

  • CVE-2021-26699MedJul 22, 2021
    risk 0.35cvss 5.4epss 0.02

    OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.

  • CVE-2020-24700MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

  • CVE-2020-12646MedAug 31, 2020
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.

  • CVE-2020-8542MedJun 16, 2020
    risk 0.35cvss 5.4epss 0.01

    OX App Suite through 7.10.3 allows XSS.

  • CVE-2019-14225MedOct 14, 2019
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.10.1 and 7.10.2 allows SSRF.

  • CVE-2019-11522MedAug 20, 2019
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.10.0 to 7.10.2 allows XSS.

  • CVE-2017-13668MedMay 23, 2019
    risk 0.35cvss 5.4epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-17061MedMay 23, 2019
    risk 0.35cvss 5.4epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

  • CVE-2017-8341MedMay 22, 2019
    risk 0.35cvss 5.3epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

Page 4 of 7