Ejabberd
Process-One · 9 CVEs
User Impersonation/Authorization Bypass in XMPP Server ejabberd
Oct 2, 2026
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to…
Oct 25, 2014
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote…
Oct 17, 2013
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a…
Feb 18, 2012
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect rec…
Jun 21, 2011
ejabberd: Remote DoS via flood of client2server messages
Feb 3, 2010
ejabberd: XSS vulnerability
Mar 18, 2009
Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.
Feb 13, 2007
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one eja…
May 5, 2006
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-104733 | User Impersonation/Authorization Bypass in XMPP Server ejabberd | HIGH | 0.21% | Oct 2, 2026 |
| CVE-2014-8760 | ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryptio… | MEDIUM | 1.31% | Oct 25, 2014 |
| CVE-2013-6169 | The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive informatio… | MEDIUM | 1.59% | Oct 17, 2013 |
| CVE-2011-4320 | The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a… | MEDIUM | 2.05% | Feb 18, 2012 |
| CVE-2011-1753 | expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which al… | MEDIUM | 2.13% | Jun 21, 2011 |
| CVE-2010-0305 | ejabberd: Remote DoS via flood of client2server messages | MEDIUM | 3.10% | Feb 3, 2010 |
| CVE-2009-0934 | ejabberd: XSS vulnerability | MEDIUM | 1.60% | Mar 18, 2009 |
| CVE-2007-0903 | Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors. | HIGH | 1.87% | Feb 13, 2007 |
| CVE-2006-2221 | A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an… | LOW | 0.37% | May 5, 2006 |
Showing 1 to 9 of 9 CVEs