📦 Mailenable

by Mailenable

🔍 What is Mailenable?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34427

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 store user and administrative passwords in plaintext within the AUTH.TAB file with overly permissive filesystem permissions. This allows any local authenticated user w...

CVE-2025-34428

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 store user and administrative passwords in plaintext within the AUTH.SAV file with overly permissive filesystem permissions. This allows any local authenticated user w...

CVE-2025-34423

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAIAU.DLL from its installation directory without proper security checks. Local attackers...

CVE-2025-34424

HIGH CVSS 7.8 Dec 10, 2025

This vulnerability allows local attackers to execute arbitrary code on MailEnable servers by planting a malicious DLL in the installation directory. Attackers with write access to the MailEnable direc...

CVE-2025-34417

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAISO.DLL from its installation directory without proper validation. Local attackers with...

CVE-2025-34418

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAIMF.DLL from its installation directory without proper security checks. Local attackers...

CVE-2025-34419

HIGH CVSS 7.8 Dec 10, 2025

This vulnerability allows local attackers with write access to MailEnable's installation directory to execute arbitrary code by planting a malicious DLL. The MailEnable administrative executable loads...

CVE-2025-34420

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAIAM.DLL from its installation directory without proper security checks. Local attackers...

CVE-2025-34421

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAISP.DLL from its installation directory without proper validation. Local attackers with...

CVE-2025-34422

HIGH CVSS 7.8 Dec 10, 2025

MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAIPC.DLL from its installation directory without proper security checks. Local attackers...

CVE-2025-34416

HIGH CVSS 7.8 Dec 10, 2025

This vulnerability allows local attackers with write access to MailEnable's installation directory to execute arbitrary code by planting a malicious DLL. It affects MailEnable versions before 10.54 an...

CVE-2025-34396

HIGH CVSS 7.3 Dec 9, 2025

MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAINFY.DLL from its directory without proper validation. Local attackers with write acces...

CVE-2025-34425

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected XSS vulnerability in the WindowContext parameter of the compose.aspx page. An attacker can craft malicious links that execute arbitrary JavaScript ...

CVE-2025-34406

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected XSS vulnerability in the Id parameter of /Mobile/ContactDetails.aspx. Attackers can craft malicious links that execute arbitrary JavaScript in vict...

CVE-2025-34407

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected cross-site scripting vulnerability in the theme parameter of Statistics.aspx. Attackers can craft malicious links that execute JavaScript in victim...

CVE-2025-34408

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. Attackers can craft maliciou...

CVE-2025-34409

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected cross-site scripting vulnerability in the Failed parameter of AddRecipientsResult.aspx. Attackers can craft malicious links that execute JavaScript...

CVE-2025-34398

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected XSS vulnerability in the AddressesBcc parameter of the AddressBook.aspx page. Attackers can craft malicious URLs that execute JavaScript in victims...

CVE-2025-34399

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected cross-site scripting vulnerability in the AddressesCc parameter of the address book page. Attackers can craft malicious URLs that execute JavaScrip...

CVE-2025-34400

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected XSS vulnerability in the AddressesTo parameter of the address book page. Attackers can craft malicious URLs that execute JavaScript in victims' bro...

CVE-2025-34401

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected XSS vulnerability in the AddressBook.aspx FieldBcc parameter. Attackers can craft malicious URLs that execute JavaScript in victims' browsers when ...

CVE-2025-34402

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected cross-site scripting vulnerability in the FieldCc parameter of the AddressBook.aspx page. Attackers can craft malicious URLs that execute JavaScrip...

CVE-2025-34403

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected XSS vulnerability in the AddressBook.aspx page's FieldTo parameter. Attackers can craft malicious URLs that execute JavaScript in victims' browsers...

CVE-2025-34404

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected cross-site scripting vulnerability in the InstanceScope parameter of the calendar compose page. This allows attackers to execute arbitrary JavaScri...

CVE-2025-34397

MEDIUM CVSS 6.1 Dec 9, 2025

MailEnable versions before 10.54 contain a reflected XSS vulnerability in the Message parameter of /Mobile/Compose.aspx. Attackers can craft malicious URLs that execute JavaScript in victims' browsers...