GNU / Mailman
47 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-43921 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third par… | MEDIUM | 5.3 | Apr 20, 2025 |
| CVE-2025-43920 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS comma… | HIGH | 8.1 | Apr 20, 2025 |
| CVE-2025-43919 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/ma… | HIGH | 7.5 | Apr 20, 2025 |
| CVE-2021-34337 | mailman: password checking timing attack in administrative REST API | HIGH | 7.6 | Apr 15, 2023 |
| CVE-2021-44227 | mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover | HIGH | 8.8 | Dec 2, 2021 |
| CVE-2021-43332 | mailman: a list moderator can crack the list admin password encrypted in a CSRF token | MEDIUM | 6.5 | Nov 12, 2021 |
| CVE-2021-43331 | mailman: XSS in Cgi/options.py via crafted URL | MEDIUM | 6.1 | Nov 12, 2021 |
| CVE-2021-42097 | mailman: CSRF token bypass allows to perform CSRF attacks and account takeover | HIGH | 8.0 | Oct 21, 2021 |
| CVE-2021-42096 | mailman: CSRF token derived from admin password allows offline brute-force attack | MEDIUM | 4.3 | Oct 21, 2021 |
| CVE-2020-15011 | mailman: arbitrary content injection via the private archive login page | MEDIUM | 4.7 | Jun 24, 2020 |
| CVE-2020-12108 | mailman: arbitrary content injection via the options login page | MEDIUM | 6.5 | May 6, 2020 |
| CVE-2020-12137 | mailman: XSS via file attachments in list archives | MEDIUM | 6.1 | Apr 24, 2020 |
| CVE-2018-0618 | mailman: Cross-site scripting vulnerability allows malicious listowners to inject scripts into listinfo pages | MEDIUM | 5.4 | Jul 26, 2018 |
| CVE-2018-13796 | mailman: Mishandled URLs in Utils.py:GetPathPieces() allows attackers to display arbitrary text on trusted sites | MEDIUM | 6.5 | Jul 12, 2018 |
| CVE-2018-5950 | mailman: Cross-site scripting (XSS) vulnerability in web UI | MEDIUM | 6.1 | Jan 23, 2018 |
| CVE-2016-7123 | mailman: Missing CSRF protection in admin web interface | HIGH | 8.8 | Sep 2, 2016 |
| CVE-2016-6893 | mailman: CSRF protection missing in the user options page | HIGH | 8.8 | Sep 2, 2016 |
| CVE-2015-2775 | mailman: directory traversal in MTA transports that deliver programmatically | HIGH | 7.6 | Apr 13, 2015 |
| CVE-2011-5024 | Cross-site scripting (XSS) vulnerability in mmsearch/design in the Mailman/htdig integration patch for Mailman allows remote attackers to inject arbitrary web… | MEDIUM | 4.3 | Dec 29, 2011 |
| CVE-2011-0707 | Mailman: Three XSS flaws due improper escaping of the full name of the member | MEDIUM | 4.3 | Feb 22, 2011 |
| CVE-2010-3089 | mailman: Multiple security flaws leading to cross-site scripting (XSS) attacks | LOW | 3.5 | Sep 15, 2010 |
| CVE-2006-2191 | Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vuln… | HIGH | 7.5 | Sep 19, 2006 |
| CVE-2006-4624 | mailman logfile CRLF injection | LOW | 2.6 | Sep 7, 2006 |
| CVE-2006-3636 | security flaw | MEDIUM | 6.8 | Sep 6, 2006 |
| CVE-2006-2941 | security flaw | MEDIUM | 5.0 | Sep 6, 2006 |
Showing 1 to 25 of 47 CVEs