Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ignite Realtime

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 50

Ignite Realtime maintains a focused vulnerability footprint centered on Openfire, a widely deployed open-source messaging and collaboration server that sits deep in enterprise communication infrastructure. The vendor's disclosures cluster around cross-site scripting vulnerabilities arising from improper input neutralization in web-facing interfaces, a pattern that reflects the server's HTTP administration and client-facing components and frequently attracts public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 86% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
2.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ignite Realtime over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Jan 26, 2026
179 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-32315HIGH
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal
May 26, 20237.598YESYES
CVE-2008-6508HIGH
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin
Mar 23, 20097.581NOYES
CVE-2015-6973MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests tha
Sep 16, 20156.862NOYES
CVE-2019-18394CRITICAL
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
Oct 24, 20199.856NOYES
CVE-2021-45967CRITICAL
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server,
Mar 18, 20229.853NOYES
CVE-2019-18393MEDIUM
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerabi
Oct 24, 20195.336NOYES
CVE-2015-6972MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName param
Sep 16, 20154.329NOYES
CVE-2015-7707MEDIUM
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.
Oct 5, 20156.528NOYES
CVE-2008-6509HIGH
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-lo
Mar 23, 20097.528NOYES
CVE-2020-12772HIGH
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an extern
May 12, 20208.826NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
76%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (62.0%)
Unknown19 (38.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (60.0%)
High1 (2.0%)
Unknown19 (38.0%)
User Interaction
None11 (22.0%)
Unknown19 (38.0%)
Required20 (40.0%)
Privileges Required
Low7 (14.0%)
High2 (4.0%)
None22 (44.0%)
Unknown19 (38.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
1 CVE
2.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
4.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
8.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
20.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ignite Realtime.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ignite Realtime — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ignite Realtime's Products

View all 6 CNAs →

Top CWEs