CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

citrix

xenmobile_server

19 known vulnerabilities · sorted by CVSS score

CVE-2018-10648
CRITICAL9.8

There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Network
Published May 23, 2018
CVE-2018-10653
CRITICAL9.8

There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Network
Published May 23, 2018
CVE-2020-8212
CRITICAL9.8

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.

citrix / xenmobile_server+15
Network
Published Aug 17, 2020
CVE-2020-8211
CRITICAL9.8

Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

citrix / xenmobile_server+20
Network
Published Aug 17, 2020
CVE-2018-18571
CRITICAL9.1

An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.

citrix / xenmobile_server+8
Network
Published Jun 5, 2019
CVE-2021-44520
HIGH8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

citrix / xenmobile_server+8
Network
Published Apr 13, 2022
CVE-2021-44519
HIGH8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

citrix / xenmobile_server+8
Network
Published Apr 19, 2022
CVE-2018-10654
HIGH8.1

There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Network
Published May 23, 2018
CVE-2018-18013
HIGH7.8

* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.

citrix / xenmobile_server
Local
Published Oct 24, 2018
CVE-2018-10650
HIGH7.8

There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Local
Published May 23, 2018
CVE-2020-8209
HIGH7.5

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

citrix / xenmobile_server+17
Network
Published Aug 17, 2020
CVE-2020-8210
HIGH7.5

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.

citrix / xenmobile_server+20
Network
Published Aug 17, 2020
CVE-2020-8253
HIGH7.5

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

citrix / xenmobile_server+17
Network
Published Sep 18, 2020
CVE-2018-10652
HIGH7.5

There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.

citrix / xenmobile_server+2
Network
Published May 23, 2018
CVE-2022-26151
HIGH7.2

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

citrix / xenmobile_server+10
Network
Published Apr 13, 2022
CVE-2018-10649
MEDIUM6.1

There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.

citrix / xenmobile_server+2
Network
Published May 23, 2018
CVE-2018-10651
MEDIUM6.1

There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Network
Published May 23, 2018
CVE-2020-8208
MEDIUM6.1

Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

citrix / xenmobile_server+17
Network
Published Aug 17, 2020
CVE-2018-18014
MEDIUM4.8

* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.

citrix / xenmobile_server
Local
Published Oct 24, 2018