Gnu Mailman vulnerabilities
47 known vulnerabilities affecting gnu/mailman.
Total CVEs
47
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
HIGH14MEDIUM30LOW3
Vulnerabilities
Page 1 of 3
CVE-2018-5950P3MEDIUMCVSS 6.1PoCfixed in 2.1.262018-01-23
CVE-2018-5950 [MEDIUM] CWE-79 CVE-2018-5950: Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attack
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
nvdosv
CVE-2015-2775P3HIGHCVSS 7.6≤ 2.1.192015-04-13
CVE-2015-2775 [HIGH] CWE-22 CVE-2015-2775: Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allow
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
nvdosv
CVE-2025-43920P3HIGHCVSS 8.1≥ 2.1.1, ≤ 2.1.39v2.1.392025-04-20
CVE-2025-43920 [HIGH] CWE-78 CVE-2025-43920: GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, all
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
nvd
CVE-2025-43919P3HIGHCVSS 7.5≥ 2.1.1, ≤ 2.1.39v2.1.392025-04-20
CVE-2025-43919 [HIGH] CWE-24 CVE-2025-43919: GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitra
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM
nvd
CVE-2002-0855P4HIGHCVSS 7.5PoCv2.0.122002-09-05
CVE-2002-0855 [HIGH] CVE-2002-0855: Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute scrip
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
nvd
CVE-2002-0388P4HIGHCVSS 7.5PoC≤ 2.0.112002-06-18
CVE-2002-0388 [HIGH] CVE-2002-0388: Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute scri
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
nvd
CVE-2006-3636P4MEDIUMCVSS 6.8PoCv2.1v2.1.1+9 more2006-09-06
CVE-2006-3636 [MEDIUM] CVE-2006-3636: Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attacker
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-6893P3HIGHCVSS 8.8v2.1v2.1.1+26 more2016-09-02
CVE-2016-6893 [HIGH] CWE-352 CVE-2016-6893: Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
nvdosv
CVE-2021-42097P3HIGHCVSS 8.0fixed in 2.1.352021-10-21
CVE-2021-42097 [HIGH] CWE-352 CVE-2021-42097: GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
nvdosv
CVE-2016-7123P3HIGHCVSS 8.8≤ 2.1.142016-09-02
CVE-2016-7123 [HIGH] CWE-352 CVE-2016-7123: Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
nvdosv
CVE-2021-44227P3HIGHCVSS 8.8fixed in 2.1.382021-12-02
CVE-2021-44227 [HIGH] CWE-352 CVE-2021-44227: In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin req
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
ghsanvdosv
CVE-2003-0038P4MEDIUMCVSS 4.3PoCv2.12003-02-07
CVE-2003-0038 [MEDIUM] CVE-2003-0038: Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to in
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
ghsanvdosv
CVE-2020-12108P3MEDIUMCVSS 6.5fixed in 2.1.312020-05-06
CVE-2020-12108 [MEDIUM] CWE-74 CVE-2020-12108: /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
nvdosv
CVE-2021-34337P3MEDIUMCVSS 6.3fixed in 3.3.52023-04-15
CVE-2021-34337 [MEDIUM] CWE-208 CVE-2021-34337: An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to liste
ghsanvdosv
CVE-2001-1132P4HIGHCVSS 7.5≤ 2.0.52001-09-05
CVE-2001-1132 [HIGH] CVE-2001-1132: Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.
nvd
CVE-2006-2191P4HIGHCVSS 7.5≤ 2.1.82006-09-19
CVE-2006-2191 [HIGH] CVE-2006-2191: Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via u
Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable.
nvdosv
CVE-2021-43332P4MEDIUMCVSS 6.5fixed in 2.1.362021-11-12
CVE-2021-43332 [MEDIUM] CWE-522 CVE-2021-43332: In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypt
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.
nvdosv
CVE-2018-13796P4MEDIUMCVSS 6.5fixed in 2.1.282018-07-12
CVE-2018-13796 [MEDIUM] CWE-20 CVE-2018-13796: An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be d
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
ghsanvdosv
CVE-2025-43921P4MEDIUMCVSS 5.3≥ 2.1.1, ≤ 2.1.39v2.1.392025-04-20
CVE-2025-43921 [MEDIUM] CWE-863 CVE-2025-43921: GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
nvd
CVE-2020-12137P4MEDIUMCVSS 6.1≥ 2.0, < 2.1.302020-04-24
CVE-2020-12137 [MEDIUM] CWE-79 CVE-2020-12137: GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME par
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, a
nvdosv
1 / 3Next →