Alinto records
16 published records for vendor alinto.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-707 Improper Neutralization2
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-308 Use of Single-factor Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2015-5395No exploit | Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.debian · debian linux · CWE-352 | High8.8 | — | 0.9% | Sep 20, 2017 |
27Monitor | CVE-2016-6188No exploit | Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to uploadalinto · sogo · CWE-399 | Medium6.5 | — | 2.2% | Feb 3, 2017 |
24Monitor | CVE-2014-9905No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web alinto · sogo · CWE-79 | Medium6.1 | — | 1.2% | Feb 17, 2017 |
24Monitor | CVE-2016-6191No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackalinto · sogo · CWE-79 | Medium6.1 | — | 1.2% | Feb 17, 2017 |
24Monitor | CVE-2023-48104Proof of concept | Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.alinto · sogo · CWE-79 | Medium6.1 | — | 1.0% | Jan 15, 2024 |
24Monitor | CVE-2022-4556Proof of concept | Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scriptingalinto · sogo · CWE-707 | Medium6.1 | — | 0.6% | Dec 16, 2022 |
24Monitor | CVE-2022-4558No exploit | Alinto SOGo Folder/Mail NSString+Utilities.m cross site scriptingalinto · sogo · CWE-707 | Medium6.1 | — | 0.6% | Dec 16, 2022 |
24Monitor | CVE-2024-24510No exploit | Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function talinto · sogo · CWE-79 | Medium6.1 | — | 0.5% | Sep 9, 2024 |
24Monitor | CVE-2020-22402No exploit | Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reaalinto · sogo web mail · CWE-79 | Medium6.1 | — | 0.4% | Jun 14, 2023 |
24Monitor | CVE-2024-34462No exploit | Alinto SOGo through 5.10.0 allows XSS during attachment preview.alinto · sogo · CWE-79 | Medium6.1 | — | 0.3% | May 4, 2024 |
24Monitor | CVE-2025-63499Proof of concept | Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.alinto · sogo · CWE-79 | Medium6.1 | — | 0.3% | Dec 4, 2025 |
24Monitor | CVE-2025-63498Proof of concept | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.alinto · sogo · CWE-79 | Medium6.1 | — | 0.3% | Nov 24, 2025 |
24Monitor | CVE-2025-71276No exploit | SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.alinto · sogo · CWE-79 | Medium6.1 | — | 0.1% | Mar 21, 2026 |
17Monitor | CVE-2016-6189No exploit | Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by readingalinto · sogo · CWE-184 | Medium4.3 | — | 1.4% | Feb 17, 2017 |
10Monitor | CVE-2026-33550No exploit | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommalinto · sogo · CWE-308 | Low2.6 | — | 0.2% | Mar 21, 2026 |
8Monitor | CVE-2026-3054No exploit | Alinto SOGo cross site scriptingalinto · sogo · CWE-79 | Low2.1 | — | 0.5% | Feb 23, 2026 |
- CVE-2015-539535Monitor
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
HighCVSS 8.8No exploitEPSS 1%debian · debian linuxSep 20, 2017
- CVE-2016-618827Monitor
Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload
MediumCVSS 6.5No exploitEPSS 2%alinto · sogoFeb 3, 2017
- CVE-2014-990524Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web
MediumCVSS 6.1No exploitEPSS 1%alinto · sogoFeb 17, 2017
- CVE-2016-619124Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attack
MediumCVSS 6.1No exploitEPSS 1%alinto · sogoFeb 17, 2017
- CVE-2023-4810424Monitor
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
MediumCVSS 6.1Proof of conceptEPSS 1%alinto · sogoJan 15, 2024
- CVE-2022-455624Monitor
Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting
MediumCVSS 6.1Proof of conceptEPSS 1%alinto · sogoDec 16, 2022
- CVE-2022-455824Monitor
Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting
MediumCVSS 6.1No exploitEPSS 1%alinto · sogoDec 16, 2022
- CVE-2024-2451024Monitor
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function t
MediumCVSS 6.1No exploitEPSS 0%alinto · sogoSep 9, 2024
- CVE-2020-2240224Monitor
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user rea
MediumCVSS 6.1No exploitEPSS 0%alinto · sogo web mailJun 14, 2023
- CVE-2024-3446224Monitor
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
MediumCVSS 6.1No exploitEPSS 0%alinto · sogoMay 4, 2024
- CVE-2025-6349924Monitor
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
MediumCVSS 6.1Proof of conceptEPSS 0%alinto · sogoDec 4, 2025
- CVE-2025-6349824Monitor
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
MediumCVSS 6.1Proof of conceptEPSS 0%alinto · sogoNov 24, 2025
- CVE-2025-7127624Monitor
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
MediumCVSS 6.1No exploitEPSS 0%alinto · sogoMar 21, 2026
- CVE-2016-618917Monitor
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading
MediumCVSS 4.3No exploitEPSS 1%alinto · sogoFeb 17, 2017
- CVE-2026-3355010Monitor
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm
LowCVSS 2.6No exploitEPSS 0%alinto · sogoMar 21, 2026
- CVE-2026-30548Monitor
Alinto SOGo cross site scripting
LowCVSS 2.1No exploitEPSS 0%alinto · sogoFeb 23, 2026