Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Axigen Mail Server CRITICAL 9.0
CVE-2025-68723

Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exis…

Fix: 10.5.57 / 10.6.26+
Fix from $2,300 2026-02-05
Axigen Mail Server MEDIUM 5.4
CVE-2025-68643

Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers …

Fix: 10.5.57 / 10.6.26+
Fix from $1,600 2026-02-05
Axigen Mail Server HIGH 8.8
CVE-2025-68722

Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface thro…

Fix: 10.5.57 / 10.6.26+
Fix from $1,950 2026-02-05
Axigen Mail Server HIGH 8.1
CVE-2025-68721

Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero pe…

Fix: 10.5.57 / 10.6.26+
Fix from $1,950 2026-02-05
Axigen Mail Server CRITICAL 9.1
CVE-2020-26942

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminP…

Fix: 10.3.1.27 / 10.3.3.1+
Fix from $2,300 2024-03-21
Axigen Mobile Webmail MEDIUM 6.1
CVE-2023-49101

WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling…

Fix: 10.3.3.61 / 10.4.24+
Fix from $1,600 2024-02-08
Axigen Mail Server CRITICAL 9.6
CVE-2023-48974

Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the s…

Fix: after 10.5.7
Fix from $2,300 2024-02-08
Axigen Mobile Webmail MEDIUM 5.4
CVE-2023-40355

Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authen…

Fix: 10.3.3.59 / 10.4.19+
Fix from $1,600 2024-02-07
Axigen Mail Server CRITICAL 9.8
CVE-2023-23566

A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an acc…

Mitigation only
Fix from $2,300 2023-01-13
Axigen Mobile Webmail MEDIUM 6.1
CVE-2022-31470EPSS 52%

An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 …

Fix: 10.2.3.12 / 10.3.3.47+
Fix from $1,600 2022-06-07
Axigen Mail Server MEDIUM 5.4
CVE-2015-5379

Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inj…

No fix yet
Fix from $1,600 2017-10-23