VendorsIgnite Realtimeopenfire4.6.0
Vulnerabilities

Ignite Realtime Igniterealtime Openfire 4.6.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2020-35200
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Published 2020-12-12 · Modified
6.1EPSS 0.009
CVE-2020-35201
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.
Published 2020-12-12 · Modified
5.4EPSS 0.007
CVE-2020-35202
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
Published 2020-12-12 · Modified
5.4EPSS 0.007
CVE-2020-35199
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
Published 2020-12-12 · Modified
5.4EPSS 0.006
CVE-2020-35127
Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
Published 2020-12-11 · Modified
5.4EPSS 0.006