sogo
Security Risk Profile
47
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 2, 2025 to present
10
Total CVEs
3
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
47/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
0High
3Medium
3Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
5
Most Affected Products
1. SOGo SOGo8
2. debian/sogo3
3. SOGo SOPE2
4. Alinto SOGo1
5. SOGo Webmail1
Recent Vulnerabilities
See more →CVE-2026-39178
CVSS 6.3medium
7/8/2026🔧 No Patch
CVE-2026-39179
CVSS 6.3medium
7/8/2026🔧 No Patch
CVE-2026-8851
CVSS 8.6EPSS 0%high
SOGo < 5.12.8 SQL Injection via addUserInAcls endpoint
5/18/2026
CVE-2026-46446
CVSS 7.1high
5/14/2026🔧 No Patch
CVE-2026-46445
CVSS 7.1high
5/14/2026
CVE-2026-33550
CVSS 2.6EPSS 0%low
3/22/2026
CVE-2025-50340
CVSS 4.3medium
8/4/2025🔧 No Patch
https://seclists.org/oss-sec/2025/q3/6
unknown
DoS segfault (NULL pointer def) in SOPE / SOGo
7/5/2025🔧 No Patch
https://seclists.org/oss-sec/2025/q3/4
unknown
DoS segfault (NULL pointer def) in SOPE / SOGo
7/2/2025🔧 No Patch
USN-8504-1
unknown
SOGo vulnerabilities
8/15/2026🔧 No Patch
Monitor sogo in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.