Alinto / SOGo
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-93453 | SOGo before 5.12.11 Password Reset Token Interception via Origin Header | HIGH | 8.7 | Sep 17, 2026 |
| CVE-2026-46446 | SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in chang… | HIGH | 7.1 | May 14, 2026 |
| CVE-2026-46445 | SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. | HIGH | 7.1 | May 14, 2026 |
| CVE-2026-33550 | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended). | LOW | 2.6 | Mar 22, 2026 |
| CVE-2025-71276 | SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories. | MEDIUM | 6.4 | Mar 22, 2026 |
| CVE-2026-3054 | Alinto SOGo cross site scripting | MEDIUM | 5.3 | Feb 24, 2026 |
| CVE-2025-63499 | Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter. | MEDIUM | 6.1 | Dec 4, 2025 |
| CVE-2025-63498 | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. | MEDIUM | 6.1 | Nov 24, 2025 |
| CVE-2024-24510 | Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail componen… | MEDIUM | 6.1 | Sep 9, 2024 |
| CVE-2024-34462 | Alinto SOGo through 5.10.0 allows XSS during attachment preview. | MEDIUM | 6.1 | May 4, 2024 |
| CVE-2023-48104 | Alinto SOGo before 5.9.1 is vulnerable to HTML Injection. | MEDIUM | 6.1 | Jan 16, 2024 |
| CVE-2022-4558 | Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting | MEDIUM | 6.1 | Dec 16, 2022 |
| CVE-2022-4556 | Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting | MEDIUM | 6.1 | Dec 16, 2022 |
| CVE-2015-5395 | Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0. | HIGH | 8.8 | Sep 20, 2017 |
| CVE-2016-6191 | Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbit… | MEDIUM | 6.1 | Feb 17, 2017 |
| CVE-2016-6189 | Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the… | MEDIUM | 4.3 | Feb 17, 2017 |
| CVE-2014-9905 | Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via… | MEDIUM | 6.1 | Feb 17, 2017 |
| CVE-2016-6188 | Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment… | MEDIUM | 6.5 | Feb 3, 2017 |
Showing 1 to 15 of 15 CVEs