i
ignite realtime
Security Risk Profile
41
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 31, 2005 to present
11
Total CVEs
2
Critical+High
1
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
5.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
41/100
medium
⚠️ 1 Active Exploits
Severity Distribution
Critical
0High
2Medium
9Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
XSS
5
2
Path Traversal
1
Most Affected Products
1. Ignite Realtime Openfire22
2. maven/org.igniterealtime.openfire:xmppserver3
3. igniterealtime Openfire3
4. Ignite Realtime Smack XMPP API2
5. maven/org.igniterealtime.openfire:openfire1
Recent Vulnerabilities
See more →CVE-2020-36956
CVSS 5.1medium
Openfire 4.6.0 - 'path' Stored XSS
Jan 26, 2026🔧 No Patch
CVE-2025-59154
CVSS 5.9medium
Openfire allows potential identity spoofing via unsafe CN parsing
Sep 15, 2025
CVE-2023-32315
CVSS 8.6high
Ignite Realtime Openfire Path Traversal Vulnerability
May 23, 2023⚠ Exploited
REDHAT-BUG-1093276
CVSS 4.0medium
May 1, 2014🔧 No Patch
REDHAT-BUG-1093273
CVSS 4.0medium
May 1, 2014🔧 No Patch
CVE-2009-0496
CVSS 4.3medium
Feb 10, 2009🔧 No Patch
CVE-2008-1728
CVSS 4.0medium
Apr 11, 2008
CVE-2007-2975
CVSS 7.5high
Jun 1, 2007
CVE-2006-7233
CVSS 4.3medium
Dec 31, 2006🔧 No Patch
CVE-2005-4877
CVSS 4.3medium
Dec 31, 2005🔧 No Patch
Monitor ignite realtime in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.