VYPR
Vendor

SquirrelMail

SquirrelMail is an open-source webmail application written in PHP. It provides a web-based interface for accessing email via the IMAP protocol and sends messages through SMTP. The project also includes a separate IMAP proxy server written in C. Both components are released under the GNU General Public License version 2 or later.

Products
11
CVEs
79
Across products
85
Status
Private

Products

11

Recent CVEs

79
View all 79 CVEs →
  • CVE-2020-14932CriJun 20, 2020
    risk 0.64cvss 9.8epss 0.01

    compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php.

  • CVE-2017-7692HigApr 20, 2017
    risk 0.63cvss 8.8epss 0.32

    SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call. It's possible to exploit this vulnerability to execute arbitrary shell commands on the remote server. The…

  • CVE-2018-8741HigMar 17, 2018
    risk 0.58cvss 8.8epss 0.04

    A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

  • CVE-2020-14933HigJun 20, 2020
    risk 0.57cvss 8.8epss 0.01

    compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup…

  • CVE-2012-5623HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

  • CVE-2025-30090HigApr 2, 2025
    risk 0.47cvss 7.2epss 0.00

    mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to true.

  • CVE-2010-1637MedJun 22, 2010
    risk 0.42cvss 6.5epss 0.03

    The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.

  • CVE-2019-12970MedJul 1, 2019
    risk 0.40cvss 6.1epss 0.02

    XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context…

  • CVE-2018-14955MedAug 5, 2018
    risk 0.40cvss 6.1epss 0.01

    The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).

  • CVE-2018-14954MedAug 5, 2018
    risk 0.40cvss 6.1epss 0.02

    The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.

  • CVE-2018-14953MedAug 5, 2018
    risk 0.40cvss 6.1epss 0.01

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

  • CVE-2018-14952MedAug 5, 2018
    risk 0.40cvss 6.1epss 0.01

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<maction xlink:href=" attack.

  • CVE-2018-14951MedAug 5, 2018
    risk 0.40cvss 6.1epss 0.01

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.

  • CVE-2018-14950MedAug 5, 2018
    risk 0.40cvss 6.1epss 0.01

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<a xlink:href=" attack.

  • CVE-2006-2842Jun 6, 2006
    risk 0.07cvss epss 0.44

    PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter. NOTE: this issue…

  • CVE-2004-0519Aug 18, 2004
    risk 0.05cvss epss 0.23

    Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.

  • CVE-2003-0990Jan 20, 2004
    risk 0.05cvss epss 0.29

    The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.

  • CVE-2002-1131Oct 4, 2002
    risk 0.05cvss epss 0.26

    Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.

  • CVE-2006-4019Aug 11, 2006
    risk 0.04cvss epss 0.10

    Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.

  • CVE-2005-1924Dec 31, 2005
    risk 0.04cvss epss 0.10

    The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php,…