Igniterealtime maintains a focused portfolio of real-time communication and collaboration products, most notably the Openfire XMPP server, Spark client, and Smack API library, which collectively serve enterprise messaging and presence infrastructure. Vulnerabilities affecting the vendor's products skew toward moderate severity and frequently acquire public exploit code, driven by recurring application-layer weakness classes including cross-site scripting, path traversal, authentication flaws, and certificate validation issues that arise across web interfaces and protocol-handling components. The exposure concentrates in the widely deployed Openfire platform and its associated tooling, where input sanitization, access control, and cryptographic validation remain persistent structural concerns. Defenders should monitor this vendor's releases for messaging-infrastructure environments and treat exposed Openfire instances as a patching priority, particularly in environments where the server handles sensitive communications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Igniterealtime over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32315HIGH Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal | May 26, 2023 | 7.5 | 98 | YES | YES |
CVE-2008-6508HIGH Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin | Mar 23, 2009 | 7.5 | 81 | NO | YES |
CVE-2015-6973MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests tha | Sep 16, 2015 | 6.8 | 62 | NO | YES |
CVE-2019-18394CRITICAL A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. | Oct 24, 2019 | 9.8 | 56 | NO | YES |
CVE-2021-45967CRITICAL An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, | Mar 18, 2022 | 9.8 | 53 | NO | YES |
CVE-2019-18393MEDIUM PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerabi | Oct 24, 2019 | 5.3 | 36 | NO | YES |
CVE-2015-6972MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName param | Sep 16, 2015 | 4.3 | 29 | NO | YES |
CVE-2015-7707MEDIUM Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. | Oct 5, 2015 | 6.5 | 28 | NO | YES |
CVE-2008-6509HIGH SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-lo | Mar 23, 2009 | 7.5 | 28 | NO | YES |
CVE-2020-12772HIGH An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an extern | May 12, 2020 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Igniterealtime.
Media articles that mention a CVE ID that affects a product developed by Igniterealtime — matched by CVE ID, not by vendor name.