Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 20 of 28
CVE-2016-0011P4MEDIUMCVSS 5.4v20132016-01-13
CVE-2016-0011 [MEDIUM] CVE-2016-0011: Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated u
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2015-6117.
nvd
CVE-2020-1345P4MEDIUMCVSS 6.1v20192020-09-11
CVE-2020-1345 [MEDIUM] CWE-79 CVE-2020-1345: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2020-1198P4MEDIUMCVSS 6.1v20192020-09-11
CVE-2020-1198 [MEDIUM] CWE-79 CVE-2020-1198: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2020-1482P4MEDIUMCVSS 6.1v20192020-09-11
CVE-2020-1482 [MEDIUM] CWE-79 CVE-2020-1482: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2019-0950P4MEDIUMCVSS 5.7v20162019-05-16
CVE-2019-0950 [MEDIUM] CVE-2019-0950: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.
nvd
CVE-2019-0949P4MEDIUMCVSS 5.7v20162019-05-16
CVE-2019-0949 [MEDIUM] CWE-79 CVE-2019-0949: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.
nvd
CVE-2019-0561P4MEDIUMCVSS 5.5v2010-sp22019-01-08
CVE-2019-0561 [MEDIUM] CVE-2019-0561: An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly
An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word.
nvd
CVE-2022-24472P4MEDIUMCVSS 5.7v2016v20192022-04-15
CVE-2022-24472 [MEDIUM] CVE-2022-24472: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2012-1863P4MEDIUMCVSS 4.3v20072012-07-10
CVE-2012-1863 [MEDIUM] CWE-79 CVE-2012-1863: Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Wind
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
nvd
CVE-2019-0562P4MEDIUMCVSS 5.4v20192019-01-08
CVE-2019-0562 [MEDIUM] CVE-2019-0562: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
nvd
CVE-2020-0891P4MEDIUMCVSS 5.4v20192020-03-12
CVE-2020-0891 [MEDIUM] CVE-2020-0891: This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted r
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'. This CVE ID is unique from CVE-2
nvd
CVE-2026-48560P4MEDIUMCVSS 5.4fixed in 16.0.19725.20384v2016+1 more2026-06-09
CVE-2026-48560 [MEDIUM] CWE-502 CVE-2026-48560: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to pe
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2020-1342P4MEDIUMCVSS 5.5v2010v20192020-07-14
CVE-2020-1342 [MEDIUM] CWE-125 CVE-2020-1342: An information disclosure vulnerability exists when Microsoft Office software reads out of bound mem
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.
nvd
CVE-2026-55026P4MEDIUMCVSS 5.5fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55026 [MEDIUM] CWE-190 CVE-2026-55026: Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose infor
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-28450P4MEDIUMCVSS 6.5v2013v2016+1 more2021-04-13
CVE-2021-28450 [MEDIUM] CVE-2021-28450: Microsoft SharePoint Denial of Service Vulnerability
Microsoft SharePoint Denial of Service Vulnerability
nvd
CVE-2015-2375P4MEDIUMCVSS 4.3v2010v20132015-07-14
CVE-2015-2375 [MEDIUM] CWE-200 CVE-2015-2375: Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services o
Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR protection mechanism via a crafted spreadsheet, aka "Microsoft Excel ASLR Bypass Vulnerability."
nvd
CVE-2011-1890P4MEDIUMCVSS 4.3v20102011-09-15
CVE-2011-1890 [MEDIUM] CWE-79 CVE-2011-1890: Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010
Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
nvd
CVE-2017-0195P4MEDIUMCVSS 5.4v20102017-04-12
CVE-2017-0195 [MEDIUM] CWE-79 CVE-2017-0195: Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office
nvd
CVE-2018-8149P4MEDIUMCVSS 5.4v2010-sp2v2013-sp1+1 more2018-05-09
CVE-2018-8149 [MEDIUM] CWE-79 CVE-2018-8149: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8
nvd
CVE-2018-8156P4MEDIUMCVSS 5.4v20162018-05-09
CVE-2018-8156 [MEDIUM] CVE-2018-8156: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2
nvd