Vulnerabilities > Open Xchange > Open Xchange Appsuite > Low

DATE CVE VULNERABILITY TITLE RISK
2020-10-23 CVE-2020-15004 Cross-site Scripting vulnerability in Open-Xchange Appsuite 7.10.2/7.10.3
OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
3.5
2020-08-31 CVE-2020-12646 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
3.5
2020-06-16 CVE-2020-8542 Cross-site Scripting vulnerability in Open-Xchange Appsuite 7.10.1/7.10.2/7.10.3
OX App Suite through 7.10.3 allows XSS.
3.5
2019-08-20 CVE-2019-11522 Cross-site Scripting vulnerability in Open-Xchange Appsuite 7.10.0/7.10.1/7.10.2
OX App Suite 7.10.0 to 7.10.2 allows XSS.
3.5
2019-08-20 CVE-2019-11806 Incorrect Permission Assignment for Critical Resource vulnerability in Open-Xchange Appsuite
OX App Suite 7.10.1 and earlier has Insecure Permissions.
local
low complexity
open-xchange CWE-732
2.1
2019-05-23 CVE-2017-13668 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
3.5
2019-05-23 CVE-2017-17061 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
3.5
2019-03-21 CVE-2018-13104 Cross-site Scripting vulnerability in Open-Xchange Appsuite
OX App Suite 7.8.4 and earlier allows XSS.
3.5
2018-06-16 CVE-2018-5754 Cross-site Scripting vulnerability in Open-Xchange Appsuite
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.
3.5
2016-12-15 CVE-2016-3173 Cross-site Scripting vulnerability in Open-Xchange Appsuite
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27.
3.5