Microsoft Sharepoint Foundation vulnerabilities
226 known vulnerabilities affecting microsoft/sharepoint_foundation.
Total CVEs
226
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH89MEDIUM116LOW10
Vulnerabilities
Page 11 of 12
CVE-2021-24104P4MEDIUMCVSS 5.4v20132021-03-11
CVE-2021-24104 [MEDIUM] CVE-2021-24104: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2012-1861P4MEDIUMCVSS 4.3v20102012-07-10
CVE-2012-1861 [MEDIUM] CWE-79 CVE-2012-1861: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoin
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."
nvd
CVE-2015-1653P4MEDIUMCVSS 4.3v20132015-04-14
CVE-2015-1653 [MEDIUM] CWE-79 CVE-2015-1653: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
nvd
CVE-2020-1205P4MEDIUMCVSS 4.6v2010v20132020-09-11
CVE-2020-1205 [MEDIUM] CVE-2020-1205: <p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a spe
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2020-1505P4MEDIUMCVSS 5.5v20132020-08-17
CVE-2020-1505 [MEDIUM] CVE-2020-1505: An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly ha
An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted
nvd
CVE-2020-1183P4MEDIUMCVSS 5.4v20132020-06-09
CVE-2020-1183 [MEDIUM] CVE-2020-1183: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.
nvd
CVE-2020-1318P4MEDIUMCVSS 5.4v2010v20132020-06-09
CVE-2020-1318 [MEDIUM] CVE-2020-1318: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1297, CVE-2020-1298, CVE-2020-1320.
nvd
CVE-2020-1177P4MEDIUMCVSS 5.4v20132020-06-09
CVE-2020-1177 [MEDIUM] CWE-79 CVE-2020-1177: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1183, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.
nvd
CVE-2020-1297P4MEDIUMCVSS 5.4v2010v20132020-06-09
CVE-2020-1297 [MEDIUM] CVE-2020-1297: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.
nvd
CVE-2020-0894P4MEDIUMCVSS 5.4v2010v20132020-03-12
CVE-2020-0894 [MEDIUM] CVE-2020-0894: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0893.
nvd
CVE-2020-16941P4MEDIUMCVSS 5.5v2010v20132020-10-16
CVE-2020-16941 [MEDIUM] CVE-2020-16941: <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly disclo
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.
To take advantage of the vulnerability, an attacker would require access to the sp
nvd
CVE-2022-21968P4MEDIUMCVSS 4.3v20132022-02-09
CVE-2022-21968 [MEDIUM] CVE-2022-21968: Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft SharePoint Server Security Feature Bypass Vulnerability
nvd
CVE-2014-4116P4MEDIUMCVSS 4.3v20102014-11-11
CVE-2014-4116 [MEDIUM] CWE-79 CVE-2014-4116: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote a
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject arbitrary web script or HTML via a modified list, aka "SharePoint Elevation of Privilege Vulnerability."
nvd
CVE-2015-6039P4LOWCVSS 3.5v20132015-10-14
CVE-2015-6039 [LOW] CWE-79 CVE-2015-6039: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foun
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content in an Office Marketplace instance, aka "Microsoft SharePoint Security Feature Bypass Vulnerability."
nvd
CVE-2015-1633P4LOWCVSS 3.5v2010v20132015-03-11
CVE-2015-1633 [LOW] CWE-79 CVE-2015-1633: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Ser
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
nvd
CVE-2015-2522P4LOWCVSS 3.5v20132015-09-09
CVE-2015-2522 [LOW] CWE-79 CVE-2015-2522: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote a
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vulnerability."
nvd
CVE-2015-6037P4LOWCVSS 3.5v20132015-10-14
CVE-2015-6037 [LOW] CWE-79 CVE-2015-6037: Cross-site scripting (XSS) vulnerability in Microsoft Excel Services on SharePoint Server 2010 SP2 a
Cross-site scripting (XSS) vulnerability in Microsoft Excel Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, Excel Web App 2010 SP2, Office Web Apps Server 2013 SP1, and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka "Microsoft Office Web Apps XSS
nvd
CVE-2015-1636P4LOWCVSS 3.5v20132015-03-11
CVE-2015-1636 [LOW] CWE-79 CVE-2015-1636: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and Sh
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
nvd
CVE-2019-1202P4MEDIUMCVSS 4.4v2010v20132019-08-14
CVE-2019-1202 [MEDIUM] CWE-200 CVE-2019-1202: An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objec
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user.
To exploit this vulnerability, the attacker could run a specially crafted application.
The security update corrects how SharePoint handl
nvd
CVE-2020-16942P4MEDIUMCVSS 4.4v2010v20132020-10-16
CVE-2020-16942 [MEDIUM] CVE-2020-16942: <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly disclo
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.
To take advantage of the vulnerability, an attacker would require access to the sp
nvd