CVE-2026-48539
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:32:59
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/Ma...
CVE-2026-48538
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:32:04
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/I...
CVE-2026-48537
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:31:11
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/F...
CVE-2026-48536
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:30:24
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/Ge...
CVE-2026-48535
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:29:17
- Zuletzt bearbeitet 27.07.2026 17:16:36
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/...
CVE-2026-48534
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:28:12
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx...
CVE-2026-48532
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:26:00
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FA...
CVE-2026-48531
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:25:13
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicy...
CVE-2026-48530
- EPSS 0.14%
- Veröffentlicht 23.07.2026 15:23:16
- Zuletzt bearbeitet 23.07.2026 17:55:03
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Ar...
CVE-2026-2039
- EPSS 0.67%
- Veröffentlicht 20.02.2026 22:13:54
- Zuletzt bearbeitet 24.02.2026 21:42:14
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerabi...