Vulnerabilities > Citrix > Storefront Server > 3.12

DATE CVE VULNERABILITY TITLE RISK
2022-04-13 CVE-2022-27503 Cross-site Scripting vulnerability in Citrix Storefront Server
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
network
high complexity
citrix CWE-79
2.6
2020-09-18 CVE-2020-8200 Improper Authentication vulnerability in Citrix Storefront Server
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
network
low complexity
citrix CWE-287
4.0
2019-08-29 CVE-2019-13608 XXE vulnerability in Citrix Storefront Server
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
network
low complexity
citrix CWE-611
5.0