VendorsAlintosogoall versions
Vulnerabilities

Alinto SOGo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2015-5395
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
Published 2017-09-20 · Modified
8.8EPSS 0.009
CVE-2016-6188
Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment, related to temporary files.
Published 2017-02-03 · Modified
6.8EPSS 0.022
CVE-2025-71276
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
Published 2026-03-22 · Analyzed
6.4EPSS 0.001
CVE-2014-9905
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title of an appointment or (2) contact fields.
Published 2017-02-17 · Modified
6.1EPSS 0.012
CVE-2016-6191
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Description, (2) Location, (3) URL, or (4) Title field.
Published 2017-02-17 · Modified
6.1EPSS 0.012
CVE-2023-48104
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
Published 2024-01-16 · Modified
6.1EPSS 0.010
CVE-2022-4556
Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting
Published 2022-12-16 · Modified
6.1EPSS 0.006
CVE-2022-4558
Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting
Published 2022-12-16 · Modified
6.1EPSS 0.006
CVE-2024-24510
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
Published 2024-09-09 · Analyzed
6.1EPSS 0.005
CVE-2026-3054
Alinto SOGo cross site scripting
Published 2026-02-24 · Analyzed
6.1EPSS 0.005
CVE-2024-34462
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
Published 2024-05-04 · Analyzed
6.1EPSS 0.003
CVE-2025-63499
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
Published 2025-12-04 · Analyzed
6.1EPSS 0.003
CVE-2025-63498
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
Published 2025-11-24 · Analyzed
6.1EPSS 0.003
CVE-2016-6189
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.
Published 2017-02-17 · Modified
4.3EPSS 0.014
CVE-2026-33550
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
Published 2026-03-22 · Analyzed
2.6EPSS 0.002