VendorsMicrosoftsharepoint_serverany version
Vulnerabilities

Microsoft Sharepoint Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

239CVEs
CVE-2026-47639
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
5.4EPSS 0.006
CVE-2026-45453
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
5.4EPSS 0.006
CVE-2026-45464
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
5.4EPSS 0.006
CVE-2026-47636
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
5.4EPSS 0.006
CVE-2026-45465
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
5.4EPSS 0.006
CVE-2026-45479
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-45483
Microsoft Office Project Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-45467
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-45462
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-64922
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
5.4EPSS 0.006
CVE-2026-45468
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-62826
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-16 · Analyzed
5.4EPSS 0.006
CVE-2026-55030
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
5.4EPSS 0.006
CVE-2026-55020
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
5.4EPSS 0.006
CVE-2026-55019
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
5.4EPSS 0.006
CVE-2026-55016
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
5.4EPSS 0.006
CVE-2026-55135
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
5.4EPSS 0.006
CVE-2026-47641
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
5.4EPSS 0.006
CVE-2026-64916
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
5.4EPSS 0.006
CVE-2026-47640
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-47638
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-47637
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
5.4EPSS 0.006
CVE-2026-64897
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
5.4EPSS 0.006
CVE-2026-64902
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
5.4EPSS 0.006
CVE-2026-56157
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
5.4EPSS 0.005
CVE-2026-62829
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
5.4EPSS 0.005
CVE-2026-69690
Microsoft Office SharePoint Spoofing Vulnerability
Published 2026-09-08 · Analyzed
5.4EPSS 0.004
CVE-2026-20958
Microsoft SharePoint Information Disclosure Vulnerability
Published 2026-01-13 · Analyzed
5.4EPSS 0.003
CVE-2023-21743
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Published 2023-01-10 · Modified
5.3EPSS 0.011
CVE-2026-69615
Microsoft Office SharePoint Spoofing Vulnerability
Published 2026-09-08 · Analyzed
4.8EPSS 0.004
CVE-2026-62917
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
4.6EPSS 0.006
CVE-2026-48562
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
4.6EPSS 0.006
CVE-2009-5092
Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2011-09-09 · Modified
4.3EPSS 0.128
CVE-2022-21968
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Published 2022-02-09 · Modified
4.3EPSS 0.021
CVE-2008-5026
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.
Published 2008-11-10 · Modified
3.5EPSS 0.094
CVE-2010-0716
_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
Published 2010-02-26 · Modified
3.5EPSS 0.086
CVE-2026-69904
Microsoft Office SharePoint Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
3.5EPSS 0.006
CVE-2026-45485
Microsoft Office Information Disclosure Vulnerability
Published 2026-06-09 · Analyzed
3.3EPSS 0.006
CVE-2023-23395
Microsoft SharePoint Server Spoofing Vulnerability
Published 2023-03-14 · Modified
3.1EPSS 0.006
← Prev6 / 6