📦

openfire

Vendor: ignite_realtime

Actively Exploited 1 CISA KEV List
PoC / Exploits 12 Code Available
Total RCEs 0 Remote Access
Total CVEs 13 Total Indexed
Avg. EPSS 8.97% Exploit Prob.
Latest CVE CVE-2024-25421 Mar 26

Security Vulnerability Index

Page 2 / 2
6.1 CVSS

Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in the Server Properties and Security Audit Viewer JSP page

EPSS: 1.01%
6.1 CVSS

In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page

EPSS: 0.62%
6.1 CVSS

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.

EPSS: 0.91%
6.1 CVSS

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.

EPSS: 0.91%
6.1 CVSS

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.

EPSS: 0.91%
6.1 CVSS

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.

EPSS: 0.91%
6.1 CVSS

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.

EPSS: 1.26%
6.1 CVSS

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.

EPSS: 1.17%
6.1 CVSS

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.

EPSS: 1.17%
6.1 CVSS

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.

EPSS: 1.41%