Superwebmailer
Products
1- 8 CVEs
Recent CVEs
8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11546 | Cri | 0.66 | 9.8 | 0.33 | Jul 14, 2020 | SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection. | ||
| CVE-2023-38193 | Hig | 0.57 | 8.8 | 0.01 | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line. | ||
| CVE-2023-38190 | Hig | 0.57 | 8.8 | 0.01 | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter. | ||
| CVE-2024-24131 | Med | 0.40 | 6.1 | 0.01 | Feb 7, 2024 | SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php. | ||
| CVE-2023-38194 | Med | 0.40 | 6.1 | 0.01 | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter. | ||
| CVE-2023-38192 | Med | 0.40 | 6.1 | 0.01 | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords. | ||
| CVE-2023-38191 | Med | 0.40 | 6.1 | 0.00 | Oct 20, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename. | ||
| CVE-2015-2349 | 0.00 | — | 0.02 | Mar 19, 2015 | Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter. |
- risk 0.66cvss 9.8epss 0.33
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.
- risk 0.40cvss 6.1epss 0.01
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.
- CVE-2015-2349Mar 19, 2015risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.