All 9 CVE vulnerabilities found in SOGo, with AI-generated Chinese analysis, references, and POCs.
Vendor: Alinto
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-93453 | SOGo before 5.12.11 Password Reset Token Interception via Origin Header CWE-640 | 8.3 | High | 2026-09-17 |
| CVE-2026-46446 | SOGo SQL注入漏洞 CWE-89 | 7.1 | High | 2026-05-14 |
| CVE-2026-46445 | SOGo SQL注入漏洞 CWE-89 | 7.1 | High | 2026-05-14 |
| CVE-2026-8496 | A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7 | - | - | 2026-05-13 |
| CVE-2026-33550 | SOGo 安全漏洞 CWE-308 | 2.0 | Low | 2026-03-22 |
| CVE-2025-71276 | SOGo 跨站脚本漏洞 CWE-79 | 6.4 | Medium | 2026-03-22 |
| CVE-2026-3054 | Alinto SOGo cross site scripting CWE-79 | 4.3 | Medium | 2026-02-24 |
| CVE-2022-4556 | Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting CWE-707 | 3.5 | Low | 2022-12-16 |
| CVE-2022-4558 | Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting CWE-707 | 3.5 | Low | 2022-12-16 |
All 9 known CVE vulnerabilities affecting SOGo with full Chinese analysis, references, and POCs where available.