Gecad develops the Axigen mail server platform, a messaging solution for small to medium deployments, where its disclosed vulnerabilities center on web-interface input handling and directory access controls. The recurring weakness classes—path traversal and cross-site scripting—reflect the web-facing attack surface typical of mail server management interfaces and web-based email clients. Current exploitation status and vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gecad over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4940MEDIUM Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) | Oct 31, 2012 | 6.4 | 86 | NO | YES |
CVE-2010-3460MEDIUM Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the | Sep 17, 2010 | 5.0 | 29 | NO | YES |
CVE-2010-3459MEDIUM Cross-site scripting (XSS) vulnerability in the Ajax WebMail interface in AXIGEN Mail Server before 7.4.2 allows remote attackers to inject arbitrary web script or HTML via unspeci | Sep 17, 2010 | 4.3 | 16 | NO | NO |
CVE-2009-1484MEDIUM Cross-site scripting (XSS) vulnerability in the web mail interface feature in AXIGEN Mail Server 6.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecifie | Apr 29, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gecad.
Media articles that mention a CVE ID that affects a product developed by Gecad — matched by CVE ID, not by vendor name.