VendorsCiscoenterprise_chat_and_emailall versions
Vulnerabilities

Cisco Enterprise Chat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2025-20139
A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.
Published 2025-04-02 · Analyzed
7.5EPSS 0.006
CVE-2024-20484
Cisco Enterprise Chat and Email Denial of Service Vulnerability
Published 2024-11-06 · Analyzed
7.5EPSS 0.006
CVE-2019-1877
Cisco Enterprise Chat and Email Attachment Download Vulnerability
Published 2019-11-05 · Modified
6.5EPSS 0.014
CVE-2019-1870
Cisco Enterprise Chat and Email Cross-Site Scripting Vulnerability
Published 2019-06-05 · Modified
6.1EPSS 0.012
CVE-2019-1702
Cisco Enterprise Chat and Email Cross-Site Scripting Vulnerabilities
Published 2019-03-11 · Modified
6.1EPSS 0.012
CVE-2022-20634
Cisco Enterprise Chat and Email Open Redirect Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.006
CVE-2022-20632
Cisco Enterprise Chat and Email Cross-Site Scripting Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.005
CVE-2022-20631
Cisco Enterprise Chat and Email Cross-Site Scripting Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.005
CVE-2025-20310
Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability
Published 2025-07-02 · Analyzed
6.1EPSS 0.003
CVE-2022-20802
Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability
Published 2022-05-27 · Modified
5.4EPSS 0.006
CVE-2024-20367
A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To successfully exploit this vulnerability, an attacker would need valid agent credentials.
Published 2024-04-03 · Analyzed
5.4EPSS 0.004
CVE-2022-20633
Cisco Enterprise Chat and Email Username Enumeration Vulnerability
Published 2024-11-15 · Analyzed
5.3EPSS 0.008