CVE-2025-71276: XSS
Last updated 6 July 2026
Other sources
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.8.0-2+deb12u3Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1 - Upgrade
Upgrade
SOGoto a version that resolves this vulnerability.Fixed in 5.12.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71276?
CVE-2025-71276 is classified as a Cross-Site Scripting (XSS) vulnerability, which can lead to significant security risks for affected users.
How do I fix CVE-2025-71276?
To fix CVE-2025-71276, upgrade SOGo to version 5.12.5 or later to eliminate the XSS vulnerability.
Which versions of SOGo are affected by CVE-2025-71276?
CVE-2025-71276 affects all versions of SOGo prior to 5.12.5.
What types of data are impacted by CVE-2025-71276?
CVE-2025-71276 exposes vulnerabilities in the management of events, tasks, and contacts, allowing potential XSS attacks.
What steps can I take beyond upgrading to mitigate CVE-2025-71276?
Beyond upgrading, you should also implement web application firewalls and content security policies to further protect against XSS vulnerabilities.