CVE-2014-2816: Microsoft SharePoint Foundation

High severity, CVSS 9.3. EPSS: 16.2% chance of exploitation in the next 30 days.

Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a Trojan horse app that executes a custom action in the context of the SharePoint extensibility model, aka "SharePoint Page Content Vulnerability."

Affected products

  • Microsoft SharePoint Foundation: version 2013 only
  • Microsoft SharePoint Server: version 2013 only

Published 2014-08-12. Last modified 2026-06-17.