📦 Axigen Mail Server

by Axigen

🔍 What is Axigen Mail Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-68723

CRITICAL CVSS 9.0 Feb 5, 2026

Axigen Mail Server versions before 10.5.57 contain multiple stored XSS vulnerabilities in the WebAdmin interface. Attackers can inject malicious JavaScript that executes in administrators' browsers, p...

CVE-2020-26942

CRITICAL CVSS 9.1 Mar 21, 2024

CVE-2020-26942 is an authentication bypass vulnerability in Axigen Mail Server that allows unauthenticated attackers to reset the administrator password via a setAdminPassword operation. This affects ...

CVE-2023-48974

CRITICAL CVSS 9.6 Feb 8, 2024

This Cross-Site Scripting (XSS) vulnerability in Axigen WebMail allows remote attackers to inject malicious scripts via the serverName_input parameter. Successful exploitation could enable privilege e...

CVE-2025-68721

HIGH CVSS 8.1 Feb 5, 2026

Axigen Mail Server versions before 10.5.57 contain an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access controls to acc...

CVE-2025-68722

HIGH CVSS 8.8 Feb 5, 2026

This CSRF vulnerability in Axigen Mail Server's WebAdmin interface allows attackers to craft malicious URLs that execute administrative actions when clicked by authenticated administrators. The vulner...

CVE-2025-68643

MEDIUM CVSS 5.4 Feb 5, 2026

Axigen Mail Server versions before 10.5.57 contain a stored cross-site scripting (XSS) vulnerability in the timeFormat account preference parameter. Attackers can inject malicious JavaScript that exec...