Open-Xchange maintains a widely deployed messaging and collaboration platform that serves enterprise customers across email, calendaring, and productivity workflows, positioning it as a high-value component in many organizational infrastructures. Despite the volume of disclosures affecting the vendor, the recurring products—chiefly Open-Xchange AppSuite and its backend infrastructure—define a concentrated footprint centered on server and integration layers rather than a sprawling portfolio. The vulnerability patterns do not consistently cluster around a single dominant weakness class, reflecting the broad surface area inherent to a full-featured collaboration suite that bridges email systems, authentication layers, and web interfaces. Defenders should track this vendor's advisory cadence for patches affecting internet-exposed collaboration services and maintain inventory of deployed versions; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open-Xchange over time
Of all the CVEs published by Open-Xchange as a CNA, 0.0% affect products that Open-Xchange develops as a vendor.
Of all the CVEs published that affect products developed by Open-Xchange, 0.0% are self-published by Open-Xchange as a CNA.
Signals from CVEs in this vendor scope (272 CVEs).
272 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4367HIGH A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ES | May 14, 2024 | 8.8 | 80 | NO | YES |
CVE-2018-5752HIGH The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to c | Jun 16, 2018 | 8.8 | 39 | NO | YES |
CVE-2018-5753MEDIUM The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to | Jun 16, 2018 | 6.5 | 36 | NO | YES |
CVE-2026-27851CRITICAL When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can | May 12, 2026 | 9.1 | 35 | NO | NO |
CVE-2020-24701MEDIUM OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI). | Jan 12, 2021 | 6.1 | 33 | NO | YES |
CVE-2018-5751MEDIUM The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated | Jun 16, 2018 | 6.5 | 33 | NO | YES |
CVE-2017-5210CRITICAL Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure. | May 23, 2019 | 9.8 | 32 | NO | NO |
CVE-2022-29851CRITICAL documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document | Oct 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-24405CRITICAL OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | Jul 27, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23100CRITICAL OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). | Jul 27, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (272 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open-Xchange.
Media articles that mention a CVE ID that affects a product developed by Open-Xchange — matched by CVE ID, not by vendor name.