CVE-2026-26930
- EPSS 0.04%
- Veröffentlicht 16.02.2026 16:27:14
- Zuletzt bearbeitet 22.02.2026 20:15:59
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.
CVE-2026-25067
- EPSS 0.03%
- Veröffentlicht 29.01.2026 03:38:02
- Zuletzt bearbeitet 29.01.2026 16:31:00
SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path witho...
CVE-2026-24423
- EPSS 29.3%
- Veröffentlicht 23.01.2026 16:53:34
- Zuletzt bearbeitet 06.02.2026 16:45:15
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS ...
CVE-2026-23760
- EPSS 59.79%
- Veröffentlicht 22.01.2026 14:35:17
- Zuletzt bearbeitet 27.01.2026 16:16:55
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token wh...
- EPSS 79.5%
- Veröffentlicht 29.12.2025 02:15:58
- Zuletzt bearbeitet 27.01.2026 15:28:07
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
CVE-2023-48116
- EPSS 0.17%
- Veröffentlicht 21.12.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:31:07
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.
CVE-2023-48115
- EPSS 0.17%
- Veröffentlicht 21.12.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:31:07
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.
CVE-2023-48114
- EPSS 0.17%
- Veröffentlicht 21.12.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:31:07
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ charac...
CVE-2021-43977
- EPSS 0.32%
- Veröffentlicht 17.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:07
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.
CVE-2021-32234
- EPSS 3.07%
- Veröffentlicht 17.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:54
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.