Gfi Software Mailessentials Ai vulnerabilities

18 known vulnerabilities affecting gfi_software/mailessentials_ai.

Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM18

Vulnerabilities

Page 1 of 1
CVE-2026-23611MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23611 [MEDIUM] CWE-79 CVE-2026-23611: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP Blocklist management page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtIPDescription parameter to /MailEssentials/pages/MailSecurity/ipblocklist.aspx, which is stored and later rendered in the manageme
cvelistv5nvd
CVE-2026-23608MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23608 [MEDIUM] CWE-79 CVE-2026-23608: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Mail Monitoring rule creation endpoint. An authenticated user can supply HTML/JavaScript in the JSON \"name\" field to /MailEssentials/pages/MailSecurity/MailMonitoring.aspx/Save, which is stored and later rendered in the management interface, allow
cvelistv5nvd
CVE-2026-23616MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23616 [MEDIUM] CWE-79 CVE-2026-23616: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spoofing configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$AntiSpoofingGeneral1$TxtSmtpDesc parameter to /MailEssentials/pages/MailSecurity/AntiSpoofing.aspx, which is stored and later rendere
cvelistv5nvd
CVE-2026-23614MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23614 [MEDIUM] CWE-79 CVE-2026-23614: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework IP Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv2$txtIPDescription parameter to /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx, which is stored and l
cvelistv5nvd
CVE-2026-23607MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23607 [MEDIUM] CWE-79 CVE-2026-23607: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spam Whitelist management interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtDescription parameter to /MailEssentials/pages/MailSecurity/Whitelist.aspx, which is stored and later rendered in the
cvelistv5nvd
CVE-2026-23620MEDIUMCVSS 5.3fixed in 22.42026-02-19
CVE-2026-23620 [MEDIUM] CWE-203 CVE-2026-23620: GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnera GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsDBExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which is URL-decoded and passed to Fil
cvelistv5nvd
CVE-2026-23610MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23610 [MEDIUM] CWE-79 CVE-2026-23610: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange configuration endpoint. An authenticated user can supply HTML/JavaScript in the POP3 server login field within the JSON \"popServers\" payload to /MailEssentials/pages/MailSecurity/POP2Exchange.aspx/Save, which is stored and later rende
cvelistv5nvd
CVE-2026-23618MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23618 [MEDIUM] CWE-79 CVE-2026-23618: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Subject) conditions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pvSubject$TXB_SubjectCondition parameter to /MailEssentials/pages/MailSecurity/ASKeywordChecking.aspx, which is s
cvelistv5nvd
CVE-2026-23606MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23606 [MEDIUM] CWE-79 CVE-2026-23606: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtRuleName parameter to /MailEssentials/pages/MailSecurity/advancedfiltering.aspx, which is stored and later re
cvelistv5nvd
CVE-2026-23617MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23617 [MEDIUM] CWE-79 CVE-2026-23617: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Body) conditions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pvGeneral$TXB_Condition parameter to /MailEssentials/pages/MailSecurity/ASKeywordChecking.aspx, which is stored and
cvelistv5nvd
CVE-2026-23609MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23609 [MEDIUM] CWE-79 CVE-2026-23609: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Perimeter SMTP Servers configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv3$txtDescription parameter to /MailEssentials/pages/MailSecurity/PerimeterSMTPServers.aspx, which is stored and later rend
cvelistv5nvd
CVE-2026-23613MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23613 [MEDIUM] CWE-79 CVE-2026-23613: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the URI DNS Blocklist configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_URIs parameter to /MailEssentials/pages/MailSecurity/uridnsblocklist.aspx, which is stored and later rendered in the mana
cvelistv5nvd
CVE-2026-23604MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23604 [MEDIUM] CWE-79 CVE-2026-23604: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/contentchecking.aspx, which is stored and later rendered in
cvelistv5nvd
CVE-2026-23612MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23612 [MEDIUM] CWE-79 CVE-2026-23612: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP DNS Blocklist configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_IPs parameter to /MailEssentials/pages/MailSecurity/ipdnsblocklist.aspx, which is stored and later rendered in the managem
cvelistv5nvd
CVE-2026-23605MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23605 [MEDIUM] CWE-79 CVE-2026-23605: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Attachment Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/attachmentchecking.aspx, which is stored and later render
cvelistv5nvd
CVE-2026-23619MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23619 [MEDIUM] CWE-79 CVE-2026-23619: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains settings page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$Pv3$txtDescription parameter to /MailEssentials/pages/MailSecurity/general.aspx, which is stored and later rendered in the management inte
cvelistv5nvd
CVE-2026-23615MEDIUMCVSS 5.1fixed in 22.42026-02-19
CVE-2026-23615 [MEDIUM] CWE-79 CVE-2026-23615: GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv4$txtEmailDescription parameter to /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx, which is stored
cvelistv5nvd
CVE-2026-23621MEDIUMCVSS 5.3fixed in 22.42026-02-19
CVE-2026-23621 [MEDIUM] CWE-203 CVE-2026-23621: GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vu GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsPathExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which is URL-decoded and pass
cvelistv5nvd