VYPR

Mailman

by CPanel

CVEs (3)

  • CVE-2020-26103HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).

  • CVE-2025-43919MedApr 20, 2025
    risk 0.38cvss 5.8epss 0.01

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report…

  • CVE-2025-43920MedApr 20, 2025
    risk 0.35cvss 5.4epss 0.01

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to…