Apache / Pony Mail
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41873 | Pony Mail: Admin account takeover via request smuggling | CRITICAL | 9.8 | Apr 28, 2026 |
| CVE-2019-0218 | A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface. | MEDIUM | 6.1 | Apr 22, 2019 |
| CVE-2017-5658 | The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derive… | MEDIUM | 5.3 | Oct 4, 2018 |
| CVE-2016-4460 | Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication. | CRITICAL | 9.8 | Aug 22, 2017 |
Showing 1 to 4 of 4 CVEs