Alinto develops SOGo, a widely deployed open-source groupware and webmail platform, which exhibits a pattern of application-layer input-handling vulnerabilities including cross-site scripting, code injection, CSRF, and improper input neutralization. These weakness classes are characteristic of web application exposure and reflect the complexity of sanitizing user input across a collaborative messaging and calendar interface. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alinto over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46446HIGH SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin. | May 14, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-46445HIGH SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. | May 14, 2026 | 7.1 | 27 | NO | NO |
CVE-2015-5395HIGH Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0. | Sep 20, 2017 | 8.8 | 25 | NO | NO |
CVE-2016-6188MEDIUM Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment, related to temporar | Feb 3, 2017 | 6.5 | 24 | NO | NO |
CVE-2025-71276MEDIUM SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories. | Mar 22, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-3054MEDIUM A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can b | Feb 24, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-63499MEDIUM Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter. | Dec 4, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-63498MEDIUM alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. | Nov 24, 2025 | 6.1 | 22 | NO | NO |
CVE-2024-34462MEDIUM Alinto SOGo through 5.10.0 allows XSS during attachment preview. | May 4, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-48104MEDIUM Alinto SOGo before 5.9.1 is vulnerable to HTML Injection. | Jan 16, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alinto.
Media articles that mention a CVE ID that affects a product developed by Alinto — matched by CVE ID, not by vendor name.