Skip to main content

Vendor archive

mailenable CVEs

Beta · best-effort

90 CVEs tagged to vendor mailenable16 Critical, 29 High, 45 Medium, 0 Low, 0 Unrated.

CVE-2025-34399

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The Address…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34398

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The Addres…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34397

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Message parameter of /Mobile/Compose.aspx. The Message value is not properly…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34396

Published Dec 9, 2025

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-44148

Published Jun 3, 2025

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42136

Published Jan 13, 2023

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12927

Published Jul 8, 2019

MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was pos…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12926

Published Jul 8, 2019

MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a number of actions, when logged in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12925

Published Jul 8, 2019

MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12924

Published Jul 8, 2019

MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12923

Published Jul 8, 2019

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by remo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9280

Published Jan 16, 2019

MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-9279

Published Jan 16, 2019

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9278

Published Jan 16, 2019

MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-9277

Published Jan 16, 2019

MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2588

Published Sep 19, 2014

Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Sub…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0389

Published Jan 24, 2012

Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2580

Published Sep 15, 2010

The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial of service (crash) via a long (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3449

Published Aug 4, 2008

MailEnable Professional 3.5.2 and Enterprise 3.52 allow remote attackers to cause a denial of service (crash) via multiple IMAP connection requests to the same folder.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0651

Published Feb 15, 2007

Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0652

Published Feb 15, 2007

Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 90 CVEsPage 2 of 4