VYPR

Axigen Mail Server

by Gecad Technologies

CVEs (4)

  • CVE-2025-68723CriFeb 5, 2026
    risk 0.59cvss 9.0epss 0.00

    Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage…

  • CVE-2025-68722HigFeb 5, 2026
    risk 0.57cvss 8.8epss 0.00

    Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and…

  • CVE-2025-68721HigFeb 5, 2026
    risk 0.53cvss 8.1epss 0.00

    Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint…

  • CVE-2025-68643MedFeb 5, 2026
    risk 0.35cvss 5.4epss 0.00

    Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the…