📦 Mailessentials

by Gfi

🔍 What is Mailessentials?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34489

HIGH CVSS 7.8 Apr 28, 2025

GFI MailEssentials versions before 21.8 contain a local privilege escalation vulnerability where an attacker with local access can send a crafted serialized payload to a .NET Remoting Service to gain ...

CVE-2026-23616

MEDIUM CVSS 5.4 Feb 19, 2026

This stored XSS vulnerability in GFI MailEssentials AI allows authenticated users to inject malicious scripts into the Anti-Spoofing configuration page. When administrators view the affected page, the...

CVE-2026-23618

MEDIUM CVSS 5.4 Feb 19, 2026

This stored XSS vulnerability in GFI MailEssentials AI allows authenticated users to inject malicious scripts into the spam keyword checking interface. When administrators view the management interfac...

CVE-2026-23620

MEDIUM CVSS 4.3 Feb 19, 2026

GFI MailEssentials AI versions before 22.4 contain an authenticated file enumeration vulnerability. An authenticated attacker can check whether arbitrary files exist on the server by manipulating the ...

CVE-2026-23614

MEDIUM CVSS 5.4 Feb 19, 2026

This stored cross-site scripting vulnerability in GFI MailEssentials AI allows authenticated users to inject malicious scripts into the Sender Policy Framework IP Exceptions interface. When administra...

CVE-2026-23608

MEDIUM CVSS 5.4 Feb 19, 2026

GFI MailEssentials AI versions before 22.4 contain a stored cross-site scripting vulnerability in the Mail Monitoring rule creation endpoint. An authenticated user can inject malicious scripts that ex...

CVE-2026-23610

MEDIUM CVSS 5.4 Feb 19, 2026

GFI MailEssentials AI versions before 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange configuration endpoint. An authenticated user can inject malicious scripts into the P...

CVE-2026-23612

MEDIUM CVSS 5.4 Feb 19, 2026

This stored cross-site scripting vulnerability in GFI MailEssentials AI allows authenticated users to inject malicious scripts into the IP DNS Blocklist configuration page. The scripts are stored and ...

CVE-2026-23604

MEDIUM CVSS 5.4 Feb 19, 2026

This stored XSS vulnerability in GFI MailEssentials AI allows authenticated users to inject malicious scripts into the keyword filtering rule creation interface. When administrators view these rules, ...

CVE-2026-23606

MEDIUM CVSS 5.4 Feb 19, 2026

This stored cross-site scripting vulnerability in GFI MailEssentials AI allows authenticated users to inject malicious scripts into the Advanced Content Filtering rule creation workflow. The scripts a...