{"api_version":"v1","generated_at":"2026-10-09T18:25:00+00:00","product":{"cve_count":8,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-alinto-sogo-f2724f54d3e3","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/sogo","name":"SOGo","next_cursor":null,"observations":[{"affected":"SOGo: < 5.12.11","affected_versions_present":true,"cve_id":"CVE-2026-93453","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-93453","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-18T18:02:43.378Z","patch_url":"","primary_source":"","published":"2026-09-17T23:25:12.890Z"},{"affected":"< 5.12.7","affected_versions_present":true,"cve_id":"CVE-2026-46446","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46446","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T13:52:19.675Z","patch_url":"","primary_source":"","published":"2026-05-14T03:13:36.276Z"},{"affected":"< 5.12.7","affected_versions_present":true,"cve_id":"CVE-2026-46445","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46445","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T13:54:20.100Z","patch_url":"","primary_source":"","published":"2026-05-14T03:10:32.528Z"},{"affected":"< 5.12.5","affected_versions_present":true,"cve_id":"CVE-2026-33550","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33550","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-23T15:53:19.737Z","patch_url":"https://github.com/Alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2","primary_source":"","published":"2026-03-22T02:16:56.263Z"},{"affected":"< 5.12.5","affected_versions_present":true,"cve_id":"CVE-2025-71276","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71276","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-02T17:57:00.835Z","patch_url":"https://github.com/Alinto/sogo/commit/e9b3f2a43d7557e8416f6749df4ab4f9128af2d1","primary_source":"","published":"2026-03-22T02:11:49.600Z"},{"affected":"5.12.3; 5.12.4","affected_versions_present":true,"cve_id":"CVE-2026-3054","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3054","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-24T20:45:48.226Z","patch_url":"","primary_source":"","published":"2026-02-24T02:02:06.992Z"},{"affected":"5.7.0; 5.7.1","affected_versions_present":true,"cve_id":"CVE-2022-4558","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-4558","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-15T13:03:15.089Z","patch_url":"https://github.com/Alinto/sogo/commit/1e0f5f00890f751e84d67be4f139dd7f00faa5f3","primary_source":"","published":"2022-12-16T00:00:00.000Z"},{"affected":"5.7.0; 5.7.1","affected_versions_present":true,"cve_id":"CVE-2022-4556","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-4556","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-15T13:03:25.339Z","patch_url":"https://github.com/Alinto/sogo/commit/efac49ae91a4a325df9931e78e543f707a0f8e5e","primary_source":"","published":"2022-12-16T00:00:00.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Alinto"}}
