Gfi Mailessentials vulnerabilities

22 known vulnerabilities affecting gfi/mailessentials.

Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM19

Vulnerabilities

Page 1 of 2
CVE-2026-23611MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23611 [MEDIUM] CWE-79 CVE-2026-23611: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP Blocklist management page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtIPDescription parameter to /MailEssentials/pages/MailSecurity/ipblocklist.aspx, which is stored and later rendered in the manageme
nvd
CVE-2026-23608MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23608 [MEDIUM] CWE-79 CVE-2026-23608: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Mail Monitoring rule creation endpoint. An authenticated user can supply HTML/JavaScript in the JSON \"name\" field to /MailEssentials/pages/MailSecurity/MailMonitoring.aspx/Save, which is stored and later rendered in the management interface, allow
nvd
CVE-2026-23620MEDIUMCVSS 5.3fixed in 22.42026-02-19
CVE-2026-23620 [MEDIUM] CWE-203 CVE-2026-23620: GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnera GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsDBExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which is URL-decoded and passed to Fil
nvd
CVE-2026-23610MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23610 [MEDIUM] CWE-79 CVE-2026-23610: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange configuration endpoint. An authenticated user can supply HTML/JavaScript in the POP3 server login field within the JSON \"popServers\" payload to /MailEssentials/pages/MailSecurity/POP2Exchange.aspx/Save, which is stored and later rende
nvd
CVE-2026-23618MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23618 [MEDIUM] CWE-79 CVE-2026-23618: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Subject) conditions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pvSubject$TXB_SubjectCondition parameter to /MailEssentials/pages/MailSecurity/ASKeywordChecking.aspx, which is s
nvd
CVE-2026-23606MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23606 [MEDIUM] CWE-79 CVE-2026-23606: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtRuleName parameter to /MailEssentials/pages/MailSecurity/advancedfiltering.aspx, which is stored and later re
nvd
CVE-2026-23607MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23607 [MEDIUM] CWE-79 CVE-2026-23607: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spam Whitelist management interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtDescription parameter to /MailEssentials/pages/MailSecurity/Whitelist.aspx, which is stored and later rendered in the
nvd
CVE-2026-23614MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23614 [MEDIUM] CWE-79 CVE-2026-23614: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework IP Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv2$txtIPDescription parameter to /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx, which is stored and l
nvd
CVE-2026-23613MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23613 [MEDIUM] CWE-79 CVE-2026-23613: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the URI DNS Blocklist configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_URIs parameter to /MailEssentials/pages/MailSecurity/uridnsblocklist.aspx, which is stored and later rendered in the mana
nvd
CVE-2026-23604MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23604 [MEDIUM] CWE-79 CVE-2026-23604: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/contentchecking.aspx, which is stored and later rendered in
nvd
CVE-2026-23616MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23616 [MEDIUM] CWE-79 CVE-2026-23616: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spoofing configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$AntiSpoofingGeneral1$TxtSmtpDesc parameter to /MailEssentials/pages/MailSecurity/AntiSpoofing.aspx, which is stored and later rendere
nvd
CVE-2026-23612MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23612 [MEDIUM] CWE-79 CVE-2026-23612: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP DNS Blocklist configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_IPs parameter to /MailEssentials/pages/MailSecurity/ipdnsblocklist.aspx, which is stored and later rendered in the managem
nvd
CVE-2026-23617MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23617 [MEDIUM] CWE-79 CVE-2026-23617: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Body) conditions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pvGeneral$TXB_Condition parameter to /MailEssentials/pages/MailSecurity/ASKeywordChecking.aspx, which is stored and
nvd
CVE-2026-23605MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23605 [MEDIUM] CWE-79 CVE-2026-23605: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Attachment Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/attachmentchecking.aspx, which is stored and later render
nvd
CVE-2026-23619MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23619 [MEDIUM] CWE-79 CVE-2026-23619: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains settings page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$Pv3$txtDescription parameter to /MailEssentials/pages/MailSecurity/general.aspx, which is stored and later rendered in the management inte
nvd
CVE-2026-23615MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23615 [MEDIUM] CWE-79 CVE-2026-23615: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv4$txtEmailDescription parameter to /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx, which is stored
nvd
CVE-2026-23621MEDIUMCVSS 5.3fixed in 22.42026-02-19
CVE-2026-23621 [MEDIUM] CWE-203 CVE-2026-23621: GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vu GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsPathExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which is URL-decoded and pass
nvd
CVE-2026-23609MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23609 [MEDIUM] CWE-79 CVE-2026-23609: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Perimeter SMTP Servers configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv3$txtDescription parameter to /MailEssentials/pages/MailSecurity/PerimeterSMTPServers.aspx, which is stored and later rend
nvd
CVE-2025-34489HIGHCVSS 7.8fixed in 21.82025-04-28
CVE-2025-34489 [HIGH] CWE-502 CVE-2025-34489: GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A loca GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service.
cvelistv5nvd
CVE-2025-34491HIGHCVSS 8.8fixed in 21.82025-04-28
CVE-2025-34491 [HIGH] CWE-502 CVE-2025-34491: GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup.
cvelistv5nvd