Vulnerabilities > Igniterealtime > Openfire

DATE CVE VULNERABILITY TITLE RISK
2019-08-23 CVE-2019-15488 Cross-site Scripting vulnerability in Igniterealtime Openfire
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
network
low complexity
igniterealtime CWE-79
6.1
2018-06-13 CVE-2018-11688 Cross-site Scripting vulnerability in Igniterealtime Openfire 3.7.1
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
low complexity
igniterealtime CWE-79
6.1
2017-10-26 CVE-2017-15911 Cross-site Scripting vulnerability in Igniterealtime Openfire
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS.
network
low complexity
igniterealtime CWE-79
4.8
2017-08-18 CVE-2014-3451 Improper Certificate Validation vulnerability in Igniterealtime Openfire
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
network
low complexity
igniterealtime CWE-295
7.5
2009-05-11 CVE-2009-1596 Improper Authentication vulnerability in Igniterealtime Openfire
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
network
low complexity
igniterealtime CWE-287
6.5