YunoHost-Apps has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.3 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- sogo_yhn 2
Worst active — by depth score
CVE-2026-74865Critical· 9.2sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication51CVE-2026-74864Critical· 9.3sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any cl…51
YunoHost-Apps vulnerabilities
CVEs affecting YunoHost-Apps, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-74865Critical· 9.2sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arb…
CVE-2026-74864Critical· 9.3sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any cl…
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any cl…