CVE Tools

Open-xchange

249 CVEs tracked since 2013. Since Sep 2013, none of them reached CISA KEV.

Open-xchange CVEs per month

Sep 2013 to Mar 2026. Point at a month, or focus the strip and use the arrow keys.
Open-xchange CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-09170
2013-1020
2013-1110
2013-12null or fewer
2014-0150
2014-02null or fewer
2014-0310
2014-0430
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-0920
2014-10null or fewer
2014-1110
2014-1220
2015-0120
2015-0210
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-0910
2015-10null or fewer
2015-1110
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12240
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-0670
2018-07null or fewer
2018-08null or fewer
2018-0960
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05200
2019-06null or fewer
2019-07null or fewer
2019-0830
2019-09null or fewer
2019-1030
2019-11null or fewer
2019-12null or fewer
2020-0170
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0660
2020-07null or fewer
2020-0840
2020-09null or fewer
2020-1030
2020-11null or fewer
2020-12null or fewer
2021-01120
2021-02null or fewer
2021-03null or fewer
2021-0440
2021-05null or fewer
2021-06null or fewer
2021-0770
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11130
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-0360
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-0750
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12100
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-0450
2023-0590
2023-0690
2023-07null or fewer
2023-08140
2023-09null or fewer
2023-10null or fewer
2023-11100
2023-12null or fewer
2024-0160
2024-0260
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03110

Products

The products that kept showing up in Open-xchange's monthly top three, with their CVEs summed over those months.

  1. Open-xchange Appsuite14428 months
  2. Ox App Suite436 months
  3. Open-xchange Appsuite Backend132 months
  4. Open-xchange Server122 months
  5. Dovecot111 month
  6. Ox Guard105 months
  7. Open-xchange Appsuite Frontend61 month
  8. Open-xchange Appsuite Office41 month
  9. Pdns41 month
  10. Open-xchange Documents31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Open-xchange.

  1. CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is l...3.1
  2. CVE-2026-42006An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left ...4.3
  3. CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to d...5.3
  4. CVE-2026-33603Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the...6.8
  5. CVE-2026-27851When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDA...7.4
  6. CVE-2026-27859A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CP...5.3
  7. CVE-2026-27860If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structu...3.7
  8. CVE-2026-27858Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeat...7.5
  9. CVE-2026-27857Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer...4.3
  10. CVE-2026-27856Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential ...7.4
  11. CVE-2026-27855Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP...6.8
  12. CVE-2026-24031Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear aut...7.7
  13. CVE-2026-0394When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the d...5.3
  14. CVE-2025-59032ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access...7.5
  15. CVE-2025-59028When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable se...5.3

The record

Peak rank
#8 in Sep 2013
Busiest month shown
Dec 2016, 24 CVEs
Months with a KEV entry
0 since Sep 2013
Monthly snapshots
38 since 2013
Open-xchange's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store