CVE-2019-18393: Ignite Realtime Openfire

Medium severity, CVSS 5.3. EPSS: 13.9% chance of exploitation in the next 30 days.

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.

Affected products

Published 2019-10-24. Last modified 2026-06-17.