Skip to main content

Vendor/product archive

igniterealtime / openfire CVEs

Beta · best-effort

37 CVEs tagged to igniterealtime / openfire3 Critical, 6 High, 28 Medium, 0 Low, 0 Unrated.

CVE-2024-25421

Published Mar 26, 2024

An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-25420

Published Mar 26, 2024

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32315

Published May 26, 2023

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversa…

CVSS 8.6 · High
evidence mentions
9
Buzz score
56.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-24604

Published Sep 2, 2020

A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24602

Published Sep 2, 2020

Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter sear…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24601

Published Sep 2, 2020

In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias"…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20526

Published Mar 19, 2020

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20525

Published Mar 19, 2020

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20527

Published Mar 19, 2020

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20528

Published Mar 18, 2020

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20366

Published Jan 8, 2020

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20365

Published Jan 8, 2020

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18394

Published Oct 24, 2019

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2019-18393

Published Oct 24, 2019

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerab…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11688

Published Jun 13, 2018

Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerabili…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15911

Published Oct 26, 2017

The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.j…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2