Known vulnerabilities in Ignite Realtime Openfire
5.0.2
5.0.1
5.0.0
4.9.2
4.9.1
4.9.0
4.8.3
4.8.2
4.8.1
4.8.0
4.7.5
4.6.8
4.7.4
4.7.3
4.7.2
4.7.1
4.7.0
4.5.6
4.6.7
4.6.6
4.5.5
4.6.5
4.6.4
4.6.3
4.6.2
4.6.1
4.6.0
3.6.0a
3.2.4
3.2.3
3.2.2
3.2.1
3.2.0
3.1.1
3.1.0
3.0.1
3.0.0
2.6.2
2.6.1
2.6.0
4.5.4
4.5.3
4.5.2
4.5.1
4.5.0
4.4.4
4.4.3
4
1
4.4.2
2
3
4.4.1
4.4.0
4.3.2
4.3.1
4.3.0
4.2.4
4.2.3
4.2.2
4.2.1
4.2.0
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0.
4.0.0
3.10.3
3.10.2
3.10.1
3.10.0
3.9.3
3.9.2
3.9.1
3.9.0
3.8.2
3.8.1
3.8.0
3.7.1
3.7.0.
3.7.0
3.6.4
3.6.3
3.6.2
3.6.1
3.6.0
3.5.2
3.5.1
3.5.0
3.4.5
3.4.4
3.4.3
3.4.2
3.4.1
3.4.0
3.3.3
3.3.2
3.3.1
3.3.0
Security bulletins (13)
| Secuity bulletin | Severity | Status | Published |
|---|---|---|---|
| SB2025091575: Identity spoofing via X.509 certificate in Openfire | Medium | 15.09.2025 | |
| SB2024030427: SQL injection in Openfire | High | 04.03.2024 | |
| SB2023052418: Authentication bypass in Openfire | High | 24.05.2023 | |
| SB2020121530: Multiple vulnerabilities in Ignite Realtime Openfire | Low | 15.12.2020 | |
| SB2020031834: Multiple vulnerabilities in Openfire | Low | 18.03.2020 | |
| SB2020010823: Multiple vulnerabilities in Openfire | Low | 08.01.2020 | |
| SB2019101201: Cross-site scripting in Openfire | Low | 12.10.2019 | |
| SB2019082313: Reflected cross-site scripting in Openfire | Low | 23.08.2019 | |
| SB2018061312: Cross-site scripting in Openfire | Low | 13.06.2018 | |
| SB2017102613: Cross-site scripting in Openfire | Low | 26.10.2017 | |
| SB2017081807: Spoofing attack in Openfire | Low | 18.08.2017 | |
| SB2015100508: Multiple vulnerabilities in Openfire | Medium | 05.10.2015 | |
| SB2014041101: Denial of service in Openfire | Medium | 11.04.2014 |