VYPR

MDaemon Mail Server

by MDaemon Technologies

CVEs (4)

  • CVE-2025-61084HigNov 5, 2025
    risk 0.46cvss 7.1epss 0.00

    MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An attacker can craft a From: header with multiple invisible Unicode thin spaces to display a spoofed sender while passing validation,…

  • CVE-2024-11182KEVNov 15, 2024
    risk 0.13cvss epss 0.17

    An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

  • CVE-2025-3929Apr 29, 2025
    risk 0.00cvss epss 0.00

    An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's…

  • CVE-2019-19497Dec 17, 2019
    risk 0.00cvss epss 0.01

    MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.