Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 19 of 28
CVE-2015-6117P4MEDIUMCVSS 6.1v20132016-01-13
CVE-2015-6117 [MEDIUM] CWE-79 CVE-2015-6117: Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated u
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2016-0011.
nvd
CVE-2020-1500P4MEDIUMCVSS 5.4v2010v20192020-08-17
CVE-2020-1500 [MEDIUM] CVE-2020-1500: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2020-1499P4MEDIUMCVSS 5.4v20192020-08-17
CVE-2020-1499 [MEDIUM] CVE-2020-1499: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2020-1501P4MEDIUMCVSS 5.4v2010v20192020-08-17
CVE-2020-1501 [MEDIUM] CVE-2020-1501: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2026-47634P4MEDIUMCVSS 5.4fixed in 16.0.19725.20384v20192026-06-09
CVE-2026-47634 [MEDIUM] CWE-74 CVE-2026-47634: Improper neutralization of special elements in output used by a downstream component ('injection') i
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-56157P4MEDIUMCVSS 5.4fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-56157 [MEDIUM] CWE-284 CVE-2026-56157: Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoo
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2025-30378P4HIGHCVSS 7.0fixed in 16.0.18526.20286v2016+1 more2025-05-13
CVE-2025-30378 [HIGH] CWE-502 CVE-2025-30378: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59232P4HIGHCVSS 7.1v2016v20192025-10-14
CVE-2025-59232 [HIGH] CWE-125 CVE-2025-59232: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2012-1862P4MEDIUMCVSS 6.8v20072012-07-10
CVE-2012-1862 [MEDIUM] CWE-20 CVE-2012-1862: Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote att
Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
nvd
CVE-2020-1443P4MEDIUMCVSS 5.4v20192020-07-14
CVE-2020-1443 [MEDIUM] CVE-2020-1443: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
nvd
CVE-2020-1454P4MEDIUMCVSS 5.4v20192020-07-14
CVE-2020-1454 [MEDIUM] CWE-79 CVE-2020-1454: This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted r
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'.
nvd
CVE-2010-1257P4MEDIUMCVSS 4.3v20072010-06-08
CVE-2010-1257 [MEDIUM] CWE-79 CVE-2010-1257: Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPa
Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization.
nvd
CVE-2020-1444P4MEDIUMCVSS 4.3v20192020-07-14
CVE-2020-1444 [MEDIUM] CVE-2020-1444: A remote code execution vulnerability exists in the way Microsoft SharePoint software parses special
A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
nvd
CVE-2026-20958P4MEDIUMCVSS 5.4fixed in 16.0.19127.20442v2016+1 more2026-01-13
CVE-2026-20958 [MEDIUM] CWE-918 CVE-2026-20958: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to d
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-54905P4HIGHCVSS 7.1v20192025-09-09
CVE-2025-54905 [HIGH] CWE-822 CVE-2025-54905: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose i
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-33129P4MEDIUMCVSS 6.5v20192023-06-14
CVE-2023-33129 [MEDIUM] CWE-122 CVE-2023-33129: Microsoft SharePoint Server Denial of Service Vulnerability
Microsoft SharePoint Server Denial of Service Vulnerability
nvd
CVE-2025-53736P4MEDIUMCVSS 6.2v20192025-08-12
CVE-2025-53736 [MEDIUM] CWE-126 CVE-2025-53736: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information lo
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2018-8378P4MEDIUMCVSS 5.5v2013-sp12018-08-15
CVE-2018-8378 [MEDIUM] CWE-125 CVE-2018-8378: An information disclosure vulnerability exists when Microsoft Office software reads out of bound mem
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microso
nvd
CVE-2012-1859P4MEDIUMCVSS 4.3v20102012-07-10
CVE-2012-1859 [MEDIUM] CWE-79 CVE-2012-1859: Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold
Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
nvd
CVE-2026-47641P4MEDIUMCVSS 5.4fixed in 16.0.19725.20384v2016+1 more2026-06-09
CVE-2026-47641 [MEDIUM] CWE-20 CVE-2026-47641: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform sp
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd