Vulnerabilities > Igniterealtime > Openfire > 4.4.4

DATE CVE VULNERABILITY TITLE RISK
2023-05-26 CVE-2023-32315 Path Traversal vulnerability in Igniterealtime Openfire
Openfire is an XMPP server licensed under the Open Source Apache License.
network
low complexity
igniterealtime CWE-22
7.5
2022-03-18 CVE-2021-45967 Path Traversal vulnerability in multiple products
An issue was discovered in Pascom Cloud Phone System before 7.20.x.
network
low complexity
pascom igniterealtime CWE-22
critical
9.8
2020-01-08 CVE-2019-20366 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
4.3
2020-01-08 CVE-2019-20365 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
4.3
2020-01-08 CVE-2019-20364 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
4.3
2020-01-08 CVE-2019-20363 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
4.3