s
sogo
Security Risk Profile
49
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 2, 2025 to present
11
Total CVEs
3
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
49/100
medium
🆕 2Fresh (<7d)📈 2 in Last 30 Days
Severity Distribution
Critical
0High
3Medium
3Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
5
2
XSS
1
Most Affected Products
1. SOGo SOGo8
2. debian/sogo3
3. SOGo SOPE2
4. SOGO SOGO Add Script to Individual Pages Header Footer WordPress plugin1
5. Alinto SOGo1
Recent Vulnerabilities
See more →CVE-2026-14835
unknown
SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post Metabox
Aug 30, 2026🔧 No Patch
CVE-2026-39178
CVSS 6.3medium
Jul 8, 2026🔧 No Patch
CVE-2026-39179
CVSS 6.3medium
Jul 8, 2026🔧 No Patch
CVE-2026-8851
CVSS 8.6EPSS 0%high
SOGo < 5.12.8 SQL Injection via addUserInAcls endpoint
May 18, 2026
CVE-2026-46446
CVSS 7.1high
May 14, 2026🔧 No Patch
CVE-2026-46445
CVSS 7.1high
May 14, 2026
CVE-2026-33550
CVSS 2.6EPSS 0%low
Mar 22, 2026
CVE-2025-50340
CVSS 4.3medium
Aug 4, 2025🔧 No Patch
https://seclists.org/oss-sec/2025/q3/6
unknown
DoS segfault (NULL pointer def) in SOPE / SOGo
Jul 5, 2025🔧 No Patch
https://seclists.org/oss-sec/2025/q3/4
unknown
DoS segfault (NULL pointer def) in SOPE / SOGo
Jul 2, 2025🔧 No Patch
Monitor sogo in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.