VYPR

Mailcow\

by Mailcow

Source repositories

CVEs (17)

  • CVE-2017-8928HigMay 14, 2017
    risk 0.60cvss 8.8epss 0.02

    mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.

  • CVE-2022-31245HigMay 20, 2022
    risk 0.58cvss 8.8epss 0.05

    mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.

  • CVE-2023-49077HigNov 30, 2023
    risk 0.54cvss 8.3epss 0.00

    Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within the Quarantine UI of the system. This vulnerability poses a significant threat to administrators who utilize the Quarantine feature.…

  • CVE-2025-25198HigFeb 12, 2025
    risk 0.49cvss 7.1epss 0.01

    mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the `Host HTTP` header to generate a password reset link pointing to an…

  • CVE-2023-26490HigMar 4, 2023
    risk 0.48cvss 7.3epss 0.02

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse…

  • CVE-2024-56529HigJan 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote…

  • CVE-2024-30270MedApr 4, 2024
    risk 0.35cvss 6.2epss 0.27

    mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability is a combination of path traversal and arbitrary code execution, specifically targeting…

  • CVE-2024-31204MedApr 4, 2024
    risk 0.33cvss 6.1epss 0.08

    mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability resides in the exception handling mechanism, specifically when not operating in DEV_MODE.…

  • CVE-2025-53909CriJul 17, 2025
    risk 0.00cvss 9.1epss 0.00

    mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template…

  • CVE-2024-41960LowAug 5, 2024
    risk 0.00cvss 3.8epss 0.00

    mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. The injected payload is executed whenever the configuration page is viewed, enabling the attacker to…

  • CVE-2024-41959HigAug 5, 2024
    risk 0.00cvss 7.6epss 0.00

    mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API logs page is viewed, potentially allowing an attacker to run malicious scripts in…

  • CVE-2024-41958MedAug 5, 2024
    risk 0.00cvss 6.6epss 0.01

    mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated attacker to bypass the 2FA protection, enabling unauthorized access to other…

  • CVE-2024-24760HigFeb 2, 2024
    risk 0.00cvss 8.8epss 0.01

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < 2024-01c. This vulnerability potentially allows attackers on the same subnet to connect to exposed ports of…

  • CVE-2024-23824MedFeb 2, 2024
    risk 0.00cvss 4.7epss 0.01

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is…

  • CVE-2023-34108HigJun 7, 2023
    risk 0.00cvss 8.8epss 0.01

    mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using…

  • CVE-2022-39258HigSep 27, 2022
    risk 0.00cvss 8.1epss 0.01

    mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a…

  • CVE-2022-31138HigJul 11, 2022
    risk 0.00cvss 8.8epss 0.03

    mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or…