Skip to main content

Vendor archive

mailenable CVEs

Beta · best-effort

90 CVEs tagged to vendor mailenable16 Critical, 29 High, 45 Medium, 0 Low, 0 Unrated.

CVE-2026-44400

Published May 8, 2026

MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication check…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-32852

Published Mar 23, 2026

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-32851

Published Mar 23, 2026

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-32850

Published Mar 23, 2026

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2025-34428

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores u…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34427

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores u…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34424

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34423

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34422

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34421

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34420

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34419

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34418

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34417

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34416

Published Dec 10, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34425

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext parameter of /Mondo/lang/sys/Forms/MAI/compose.aspx. The Windo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34409

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34408

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The A…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34407

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter of /Mondo/lang/sys/Forms/Statistics.aspx. The theme value is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34406

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /Mobile/ContactDetails.aspx. The Id value is not properly sa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34404

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope parameter of /Mondo/lang/sys/Forms/CAL/compose.aspx. The Insta…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34403

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldTo val…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34402

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldCc val…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34401

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldBcc v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34400

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The Address…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 90 CVEsPage 1 of 4