← Back

Totemomail

totemomail

Vendor: Totemo • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totemo
1Totemomail
Jun 17, 2025
May 18, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.
1Totemo
1Totemomail
Nov 21, 2024
Mar 27, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.
1Totemo
1Totemomail
Nov 21, 2024
Aug 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
1Totemo
1Totemomail
Nov 21, 2024
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
1Totemo
1Totemomail
Nov 21, 2024
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
1Totemo
1Totemomail
Nov 21, 2024
Aug 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.