CVE-2025-30191: Open-Xchange GmbH Ox App Suite

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure. No publicly available exploits are known

Affected products

  • Open-Xchange GmbH Ox App Suite: up to and including 7.6.3-rev77; up to and including 8.35.111; up to and including 8.38.82; up to and including 8.39.79; up to and including 8.40.57

Published 2025-10-31. Last modified 2026-10-07.