Known Vulnerabilities for SOGo by Alinto SOGo
Listed below are 5 of the newest known vulnerabilities associated with "SOGo" by "Alinto SOGo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-93453 json | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauth... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-39179 json | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the ne... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-39178 json | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the se... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-14835 json | The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom hea... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-8496 json | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitat... | Not Provided | 2026-05-13 | 2026-08-06 |