Mailman
by CPanel
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26103 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551). | ||
| CVE-2025-43919 | Med | 0.38 | 5.8 | 0.01 | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report… | ||
| CVE-2025-43920 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2025 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to… |
- risk 0.49cvss 7.5epss 0.01
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
- risk 0.38cvss 5.8epss 0.01
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report…
- risk 0.35cvss 5.4epss 0.01
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to…