Open Exchange Ox App Suite
By the Year
In 2024 there have been 0 vulnerabilities in Open Exchange Ox App Suite . Ox App Suite did not have any published security vulnerabilities last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 0 | 0.00 |
2023 | 0 | 0.00 |
2022 | 0 | 0.00 |
2021 | 4 | 5.93 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Ox App Suite vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Open Exchange Ox App Suite Security Vulnerabilities
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18
CVE-2021-37403
6.1 - Medium
- July 22, 2021
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.
XSS
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data
CVE-2021-37402
6.1 - Medium
- July 22, 2021
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
XSS
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document
CVE-2021-26699
5.4 - Medium
- July 22, 2021
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
XSPA
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18
CVE-2021-26698
6.1 - Medium
- July 22, 2021
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and the dl parameter is used.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Open Xchange Appsuite or by Open Exchange? Click the Watch button to subscribe.