Show filters
202 Total Results
Displaying 1-10 of 202
Sort by:
Attacker Value
Unknown

CVE-2023-43770

Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
Attacker Value
Unknown

CVE-2024-42009

Disclosure Date: August 05, 2024 (last updated September 07, 2024)
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Attacker Value
Unknown

CVE-2024-42008

Disclosure Date: August 05, 2024 (last updated September 07, 2024)
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
Attacker Value
Unknown

CVE-2024-37383

Disclosure Date: June 07, 2024 (last updated October 26, 2024)
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Attacker Value
Unknown

CVE-2023-49101

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates.
Attacker Value
Unknown

CVE-2024-24131

Disclosure Date: February 07, 2024 (last updated February 13, 2024)
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
Attacker Value
Unknown

CVE-2023-40355

Disclosure Date: February 07, 2024 (last updated February 15, 2024)
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.
Attacker Value
Unknown

CVE-2023-47272

Disclosure Date: November 06, 2023 (last updated December 29, 2023)
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Attacker Value
Unknown

CVE-2023-38194

Disclosure Date: October 21, 2023 (last updated October 28, 2023)
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
Attacker Value
Unknown

CVE-2023-38193

Disclosure Date: October 21, 2023 (last updated October 28, 2023)
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.