Afterlogic develops a focused suite of web-based email and file-management applications, including Aurora, WebMail Pro, and MailBee WebMail, that serve as self-hosted or cloud-hosted messaging and collaboration platforms. Its vulnerability exposure recurs through application-layer input-handling and deserialization weaknesses—chiefly cross-site scripting, path traversal, and untrusted deserialization—which are characteristic of server-side web applications handling user input and file operations, and the vendor's disclosures frequently acquire public exploit code. Defenders should treat Afterlogic patches as priority for internet-facing instances and monitor for proof-of-concept tooling; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Afterlogic over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26294HIGH An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file co | Mar 7, 2021 | 7.5 | 43 | NO | YES |
CVE-2021-26293CRITICAL An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an execut | Mar 4, 2021 | 9.8 | 33 | NO | NO |
CVE-2008-0333MEDIUM Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot d | Jan 17, 2008 | 5.0 | 31 | NO | YES |
CVE-2023-43176HIGH A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file. | Oct 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2012-2587MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with a | Aug 12, 2012 | 4.3 | 24 | NO | YES |
CVE-2008-0631MEDIUM Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddSt | Feb 6, 2008 | 4.3 | 24 | NO | YES |
CVE-2007-5290MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and | Oct 9, 2007 | 4.3 | 24 | NO | YES |
CVE-2025-12460MEDIUM An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img HTML tag. T | Oct 31, 2025 | 5.3 | 21 | NO | NO |
CVE-2019-16238MEDIUM Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login. | Sep 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2009-4743MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or HT | Mar 26, 2010 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Afterlogic.
Media articles that mention a CVE ID that affects a product developed by Afterlogic — matched by CVE ID, not by vendor name.