VDB
CVE-2026-3054
CVE-2026-3054
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
EPSS 0.40% · 33.8th percentile
Risk Scores
CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
EPSS Score
0.40%
33.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alinto | SOGo | 5.12.4, 5.12.3, 5.12.4 |
| alinto | sogo | 5.12.3, 5.12.3, 5.12.4 |
Timeline
- Feb 23, 2026 CVE ID Reserved
- Feb 24, 2026 EPSS Score
- Feb 24, 2026 CVE Published
- Feb 24, 2026 PoC Published
- Feb 24, 2026 CVE Updated
- Feb 26, 2026 EPSS Score
- Feb 28, 2026 EPSS Score
- Mar 2, 2026 EPSS Score
- Mar 3, 2026 EPSS Score
- Mar 5, 2026 EPSS Score
- Mar 7, 2026 EPSS Score
- Mar 9, 2026 EPSS Score