Skip to content
Noroxi

Alinto records

16 published records for vendor alinto.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

16 records
  • CVE-2015-5395
    35Monitor

    Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.

    HighCVSS 8.8No exploitEPSS 1%

    debian · debian linuxSep 20, 2017

  • CVE-2016-6188
    27Monitor

    Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload

    MediumCVSS 6.5No exploitEPSS 2%

    alinto · sogoFeb 3, 2017

  • CVE-2014-9905
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web

    MediumCVSS 6.1No exploitEPSS 1%

    alinto · sogoFeb 17, 2017

  • CVE-2016-6191
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attack

    MediumCVSS 6.1No exploitEPSS 1%

    alinto · sogoFeb 17, 2017

  • Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    alinto · sogoJan 15, 2024

  • CVE-2022-4556
    24Monitor

    Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting

    MediumCVSS 6.1Proof of conceptEPSS 1%

    alinto · sogoDec 16, 2022

  • CVE-2022-4558
    24Monitor

    Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    alinto · sogoDec 16, 2022

  • Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function t

    MediumCVSS 6.1No exploitEPSS 0%

    alinto · sogoSep 9, 2024

  • Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user rea

    MediumCVSS 6.1No exploitEPSS 0%

    alinto · sogo web mailJun 14, 2023

  • Alinto SOGo through 5.10.0 allows XSS during attachment preview.

    MediumCVSS 6.1No exploitEPSS 0%

    alinto · sogoMay 4, 2024

  • Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

    MediumCVSS 6.1Proof of conceptEPSS 0%

    alinto · sogoDec 4, 2025

  • alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

    MediumCVSS 6.1Proof of conceptEPSS 0%

    alinto · sogoNov 24, 2025

  • SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

    MediumCVSS 6.1No exploitEPSS 0%

    alinto · sogoMar 21, 2026

  • CVE-2016-6189
    17Monitor

    Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading

    MediumCVSS 4.3No exploitEPSS 1%

    alinto · sogoFeb 17, 2017

  • SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm

    LowCVSS 2.6No exploitEPSS 0%

    alinto · sogoMar 21, 2026

  • Alinto SOGo cross site scripting

    LowCVSS 2.1No exploitEPSS 0%

    alinto · sogoFeb 23, 2026