Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smartermail HIGH 8.8
CVE-2026-7807

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that all…

Fix: 100.0.9560+
Fix from $1,950 2026-05-08
Smartermail CRITICAL 9.1
CVE-2026-40514

SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption wi…

Fix: 100.0.9610+
Fix from $2,300 2026-04-27
Smartermail MEDIUM 5.3
CVE-2026-25067

SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview en…

Fix: 100.0.9518+
Fix from $1,600 2026-01-29
Smartermail CRITICAL 9.8
CVE-2026-24423 KEVEPSS 88%

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. …

Fix: 100.0.9511+
Fix from $2,300 2026-01-23
Smartermail CRITICAL 9.8
CVE-2026-23760 KEVEPSS 96%

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw…

Fix: 100.0.9511+
Fix from $2,300 2026-01-22
Smartertrack MEDIUM 5.3
CVE-2020-36926

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Atta…

No fix yet
Fix from $1,600 2026-01-16
Smartermail CRITICAL 10.0
CVE-2025-52691 KEVEPSS 85%

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po…

Fix: 100.0.9413+
Fix from $2,300 2025-12-29
Smartermail MEDIUM 5.4
CVE-2023-48114

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the…

Fix: 16.0.8747+
Fix from $1,600 2023-12-21
Smartermail MEDIUM 5.4
CVE-2023-48115

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and mess…

Fix: 16.0.8747+
Fix from $1,600 2023-12-21
Smartermail MEDIUM 5.4
CVE-2023-48116

SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.

Fix: 16.0.8747+
Fix from $1,600 2023-12-21
Smartertrack HIGH 7.2
CVE-2022-24387

With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml f…

Fix: 100.0.8075+
Fix from $1,950 2022-03-14
Smartertrack MEDIUM 6.5
CVE-2022-24385

A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0…

Fix: 100.0.8075+
Fix from $1,600 2022-03-14
Smartertrack MEDIUM 6.1
CVE-2022-24384

Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

Fix: 100.0.8075+
Fix from $1,600 2022-03-14
Smartertrack MEDIUM 6.1
CVE-2022-24386

Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

Fix: 100.0.8075+
Fix from $1,600 2022-03-14
Smartermail CRITICAL 9.8
CVE-2021-32234

SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.

Fix: 100.0.7803+
Fix from $2,300 2021-11-17
Smartermail MEDIUM 6.1
CVE-2021-43977

SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.

Fix: 100.0.7803+
Fix from $1,600 2021-11-17
Smartermail MEDIUM 5.4
CVE-2021-40377

SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and…

Fix: 16.3.7866+
Fix from $1,600 2021-09-08
Smartermail HIGH 8.1
CVE-2020-29548

An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS comma…

Fix: after 100.0.7537
Fix from $1,950 2021-08-17
Smartermail MEDIUM 6.1
CVE-2021-32233

SmarterTools SmarterMail before Build 7776 allows XSS.

Fix: 16.3.7776+
Fix from $1,600 2021-07-06
Smartermail CRITICAL 9.8
CVE-2019-7214EPSS 85%

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the serve…

Fix: 16.3.6985+
Fix from $2,300 2019-04-24
Smartermail MEDIUM 6.5
CVE-2019-7213EPSS 42%

SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files …

Fix: 16.3.6985+
Fix from $1,600 2019-04-24
Smartermail HIGH 8.2
CVE-2019-7212

SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file atta…

Fix: 16.3.6985+
Fix from $1,950 2019-04-24
Smartermail MEDIUM 6.1
CVE-2019-7211

SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by opening a malicious email or …

Fix: 16.3.6955+
Fix from $1,600 2019-04-24
Smartermail MEDIUM 6.1
CVE-2015-9276

SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code w…

Fix: 13.3.5535+
Fix from $1,600 2019-01-16
Smarterstats MEDIUM 6.1
CVE-2017-14620

SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cro…

No fix yet
Fix from $1,600 2017-09-30
Smarterstats HIGH 10.0
CVE-2011-4752

SmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecif…

Mitigation only
Fix from $1,950 2011-12-16
Smarterstats MEDIUM 5.0
CVE-2011-4751

SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted…

Mitigation only
Fix from $1,600 2011-12-16
Smarterstats HIGH 10.0
CVE-2011-2148EPSS 5%

Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a lead…

Mitigation only
Fix from $1,950 2011-05-20
Smarterstats HIGH 10.0
CVE-2011-2158

The SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have a…

Mitigation only
Fix from $1,950 2011-05-20
Smarterstats HIGH 10.0
CVE-2011-2159

The SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have an unspe…

Mitigation only
Fix from $1,950 2011-05-20