VYPR

Mailenable

by MailEnable

CVEs (81)

  • CVE-2025-34396HigDec 9, 2025
    risk 0.47cvss 7.3epss 0.00

    MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAINFY.DLL from its application directo without sufficient integrity validation or secure…

  • CVE-2019-12923MedJul 8, 2019
    risk 0.42cvss 6.5epss 0.01

    In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a…

  • CVE-2026-32852MedMar 23, 2026
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the…

  • CVE-2026-32851MedMar 23, 2026
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the…

  • CVE-2026-32850MedMar 23, 2026
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the…

  • CVE-2025-34425MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext parameter of /Mondo/lang/sys/Forms/MAI/compose.aspx. The WindowContext value is not properly sanitized when processed via a GET request and is reflected within a…

  • CVE-2025-34409MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Failed value is not properly sanitized when processed via a GET request and is reflected in the…

  • CVE-2025-34408MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Added value is not properly sanitized when processed via a GET request and is reflected in the…

  • CVE-2025-34407MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter of /Mondo/lang/sys/Forms/Statistics.aspx. The theme value is insufficiently sanitized when processed via a GET request and is reflected in the response,…

  • CVE-2025-34406MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /Mobile/ContactDetails.aspx. The Id value is not properly sanitized when processed via a GET request and is reflected within a block in the response.…

  • CVE-2025-34404MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope parameter of /Mondo/lang/sys/Forms/CAL/compose.aspx. The InstanceScope value is not properly sanitized when processed via a GET request and is reflected inside a…

  • CVE-2025-34403MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldTo value is not properly sanitized when processed via a GET request and is reflected inside a …

  • CVE-2025-34402MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldCc value is not properly sanitized when processed via a GET request and is reflected inside a …

  • CVE-2025-34401MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldBcc value is not properly sanitized when processed via a GET request and is reflected inside a …

  • CVE-2025-34400MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesTo value is not properly sanitized when processed via a GET request and is reflected within a…

  • CVE-2025-34399MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a…

  • CVE-2025-34398MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesBcc value is not properly sanitized when processed via a GET request and is reflected within a…

  • CVE-2025-34397MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Message parameter of /Mobile/Compose.aspx. The Message value is not properly sanitized when processed via a GET request and is reflected into a JavaScript context in the…

  • CVE-2019-12927MedJul 8, 2019
    risk 0.40cvss 6.1epss 0.01

    MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.

  • CVE-2015-9279MedJan 16, 2019
    risk 0.40cvss 6.1epss 0.01

    MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

Page 2 of 5