Vulnerabilities > Igniterealtime > Openfire > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2021-45967 Path Traversal vulnerability in multiple products
An issue was discovered in Pascom Cloud Phone System before 7.20.x.
network
low complexity
pascom igniterealtime CWE-22
critical
9.8
2019-10-24 CVE-2019-18394 Server-Side Request Forgery (SSRF) vulnerability in Igniterealtime Openfire
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
network
low complexity
igniterealtime CWE-918
critical
9.8