Filter
AND

Open-xchange Ox App SuiteOX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from …

First published (updated )

Open-xchange Ox App SuiteOX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentia…

First published (updated )

Open-xchange Ox App SuiteOX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., …

First published (updated )

Open-xchange Ox App SuiteOX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of ar…

First published (updated )

Open-xchange Ox App SuiteOX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lis…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Open-xchange Ox App SuiteOX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail mes…

First published (updated )

Open-xchange Ox App SuiteOX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for r…

First published (updated )

Open-xchange Ox App SuiteXSS

First published (updated )

Open-xchange Ox App SuiteXSS

First published (updated )

Open-xchange Open-xchange Appsuite BackendWhen adding an external mail account, processing of SMTP "capabilities" responses are not limited to…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

CVE-2023-26456XSS

First published (updated )

CVE-2023-29043XSS

First published (updated )

Open-xchange Open-xchange AppsuiteProcessing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could…

First published (updated )

Open-xchange Open-xchange AppsuiteProcessing time of drive search expressions now gets monitored, and the related request is terminate…

First published (updated )

Open-xchange Open-xchange AppsuiteProcessing of user-defined mail search expressions is not limited. Availability of OX App Suite coul…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Open-xchange Open-xchange AppsuiteXSS

First published (updated )

Open-xchange Open-xchange AppsuiteXSS

First published (updated )

Open-xchange Open-xchange Appsuite BackendCommand Injection

First published (updated )

Open-xchange Open-xchange ServerPath Traversal

First published (updated )

Htmlcleaner Project HtmlcleanerRace Condition

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Open-xchange Open-xchange AppsuiteInfoleak

First published (updated )

Open-xchange Open-xchange AppsuiteOpen-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 has a hardcoded password…

First published (updated )

Open-xchange Open-xchange AppsuiteCode Injection, CRLF Injection

First published (updated )

Open-xchange Open-xchange AppsuiteCode Injection, CRLF Injection

First published (updated )

Open-xchange Open-xchangeXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Open-xchange Open-xchange AppsuiteXSS

First published (updated )

Open-xchange Open-xchange AppsuiteInfoleak

First published (updated )

Open-xchange Open-xchange AppsuiteXSS

First published (updated )

Open-xchange Open-xchange AppsuiteXSS

First published (updated )

Open-xchange Open-xchange AppsuiteInfoleak

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203