Show filters
202 Total Results
Displaying 1-10 of 202
Sort by:
Attacker Value
Unknown
CVE-2023-43770
Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
1
Attacker Value
Unknown
CVE-2024-42009
Disclosure Date: August 05, 2024 (last updated September 07, 2024)
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
0
Attacker Value
Unknown
CVE-2024-42008
Disclosure Date: August 05, 2024 (last updated September 07, 2024)
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
0
Attacker Value
Unknown
CVE-2024-37383
Disclosure Date: June 07, 2024 (last updated October 26, 2024)
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
0
Attacker Value
Unknown
CVE-2023-49101
Disclosure Date: February 08, 2024 (last updated February 16, 2024)
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates.
0
Attacker Value
Unknown
CVE-2024-24131
Disclosure Date: February 07, 2024 (last updated February 13, 2024)
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
0
Attacker Value
Unknown
CVE-2023-40355
Disclosure Date: February 07, 2024 (last updated February 15, 2024)
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.
0
Attacker Value
Unknown
CVE-2023-47272
Disclosure Date: November 06, 2023 (last updated December 29, 2023)
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
0
Attacker Value
Unknown
CVE-2023-38194
Disclosure Date: October 21, 2023 (last updated October 28, 2023)
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
0
Attacker Value
Unknown
CVE-2023-38193
Disclosure Date: October 21, 2023 (last updated October 28, 2023)
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
0