Mailcow

Mailcow: Dockerized

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 17.07.2025 13:47:26
  • Zuletzt bearbeitet 11.09.2025 20:16:06

mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantin...

  • EPSS 2.64%
  • Veröffentlicht 12.02.2025 18:15:27
  • Zuletzt bearbeitet 01.10.2025 17:39:39

mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the `Host HTTP` header to generate a password reset lin...

  • EPSS 30.31%
  • Veröffentlicht 05.08.2024 20:15:36
  • Zuletzt bearbeitet 20.09.2024 12:58:23

mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated attacker to bypass the 2FA protection, enabling unaut...

  • EPSS 0.85%
  • Veröffentlicht 05.08.2024 20:15:36
  • Zuletzt bearbeitet 19.09.2024 20:14:02

mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API logs page is viewed, potentially allowing an attacke...

  • EPSS 0.43%
  • Veröffentlicht 05.08.2024 20:15:36
  • Zuletzt bearbeitet 19.09.2024 20:01:58

mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. The injected payload is executed whenever the configuration page is viewed, e...

Exploit
  • EPSS 49.44%
  • Veröffentlicht 04.04.2024 21:15:16
  • Zuletzt bearbeitet 06.10.2025 15:10:52

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability is a combination of path traversal and arbitrary code executi...

  • EPSS 4.05%
  • Veröffentlicht 02.02.2024 16:15:56
  • Zuletzt bearbeitet 21.11.2024 08:59:38

mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < 2024-01c. This vulnerability potentially allows attackers on the same subnet t...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 02.02.2024 16:15:55
  • Zuletzt bearbeitet 21.11.2024 08:58:29

mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't resp...

  • EPSS 0.43%
  • Veröffentlicht 30.11.2023 07:15:08
  • Zuletzt bearbeitet 21.11.2024 08:32:46

Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability has been identified within the Quarantine UI of the system. This vulnerability poses a significant threat to administrators who ut...

  • EPSS 0.51%
  • Veröffentlicht 07.06.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:33

mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dove...