cbcvebase.

Microsoft Sharepoint Server vulnerabilities

548 known vulnerabilities affecting microsoft/sharepoint_server.

Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15

Vulnerabilities

Page 24 of 28
CVE-2026-45479P4MEDIUMCVSS 5.4fixed in 16.0.19725.20384v2016+1 more2026-06-09
CVE-2026-45479 [MEDIUM] CWE-79 CVE-2026-45479: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-45467P4MEDIUMCVSS 5.4fixed in 16.0.19725.20384v2016+1 more2026-06-09
CVE-2026-45467 [MEDIUM] CWE-79 CVE-2026-45467: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-45483P4MEDIUMCVSS 5.4fixed in 16.0.19725.20384v2016+1 more2026-06-09
CVE-2026-45483 [MEDIUM] CWE-79 CVE-2026-45483: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-55020P4MEDIUMCVSS 5.4fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55020 [MEDIUM] CWE-79 CVE-2026-55020: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-55016P4MEDIUMCVSS 5.4fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55016 [MEDIUM] CWE-79 CVE-2026-55016: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-55135P4MEDIUMCVSS 5.4fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55135 [MEDIUM] CWE-79 CVE-2026-55135: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-62826P4MEDIUMCVSS 5.4fixed in 16.0.19725.20434v2016+1 more2026-07-16
CVE-2026-62826 [MEDIUM] CWE-79 CVE-2026-62826: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2013-0083P4MEDIUMCVSS 4.3v20102013-03-13
CVE-2013-0083 [MEDIUM] CWE-79 CVE-2013-0083: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attac Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
nvd
CVE-2020-1583P4MEDIUMCVSS 5.5v2010v20192020-08-17
CVE-2020-1583 [MEDIUM] CVE-2020-1583: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1502P4MEDIUMCVSS 5.5v20192020-08-17
CVE-2020-1502 [MEDIUM] CVE-2020-1502: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1503P4MEDIUMCVSS 5.5v2010v20192020-08-17
CVE-2020-1503 [MEDIUM] CVE-2020-1503: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-16950P4MEDIUMCVSS 5.5v20192020-10-16
CVE-2020-16950 [MEDIUM] CVE-2020-16950: <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafte
nvd
CVE-2020-1323P4MEDIUMCVSS 6.1v2013v20192020-06-09
CVE-2020-1323 [MEDIUM] CWE-601 CVE-2020-1323: An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
nvd
CVE-2018-0864P4MEDIUMCVSS 5.4v2013v20162018-02-15
CVE-2018-0864 [MEDIUM] CWE-79 CVE-2018-0864: SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
nvd
CVE-2017-8629P4MEDIUMCVSS 5.4v20132017-09-13
CVE-2017-8629 [MEDIUM] CWE-79 CVE-2017-8629: Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint XSS Vulnerability".
nvd
CVE-2014-1754P4MEDIUMCVSS 4.3v20132014-05-14
CVE-2014-1754 [MEDIUM] CWE-79 CVE-2014-1754: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoin Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
nvd
CVE-2019-1442P4MEDIUMCVSS 5.5v20192019-11-12
CVE-2019-1442 [MEDIUM] CWE-346 CVE-2019-1442: A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attac A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
nvd
CVE-2020-1456P4MEDIUMCVSS 5.4v2010v20192020-07-14
CVE-2020-1456 [MEDIUM] CVE-2020-1456: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1451.
nvd
CVE-2019-0558P4MEDIUMCVSS 5.4v2013-sp1v2016+1 more2019-01-08
CVE-2019-0558 [MEDIUM] CVE-2019-0558: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from
nvd
CVE-2020-0924P4MEDIUMCVSS 5.4v20192020-04-15
CVE-2020-0924 [MEDIUM] CVE-2020-0924: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0954,
nvd
Microsoft Sharepoint Server vulnerabilities | cvebase