← Back

Mdaemon

mdaemon

4 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Mdaemon
mdaemon
Email Server
email_server

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mdaemon
1Email Server
Jun 17, 2026
Apr 29, 2025
5.3 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitra...Show more
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.Show less
1Mdaemon
1Mdaemon
Jun 17, 2026
Nov 15, 2024
5.3 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript...Show more
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.Show less
1Mdaemon
1Securitygateway
Jun 17, 2026
Dec 31, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators.
1Mdaemon
1Mdaemon
Apr 16, 2026
Dec 31, 2002
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords.