VYPR

Superwebmailer

by Superwebmailer

CVEs (8)

  • CVE-2020-11546CriJul 14, 2020
    risk 0.66cvss 9.8epss 0.33

    SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

  • CVE-2023-38193HigOct 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.

  • CVE-2023-38190HigOct 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.

  • CVE-2024-24131MedFeb 7, 2024
    risk 0.40cvss 6.1epss 0.01

    SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.

  • CVE-2023-38194MedOct 21, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.

  • CVE-2023-38192MedOct 21, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.

  • CVE-2023-38191MedOct 20, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.

  • CVE-2015-2349Mar 19, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.