Mailman
Vendor:
First CVE: Oct 20, 2000 · Active for 25 years
47
Total CVEs
More Total CVEs than 97% of tracked products
2.9
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mailman over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Apr 20, 2025
460 days ago
CVE Severity & Scoring
Mailman47 CVEs
9%
62%
30%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (2.1%)
Network16 (34.0%)
Unknown30 (63.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (31.9%)
High2 (4.3%)
Unknown30 (63.8%)
User Interaction
None6 (12.8%)
Unknown30 (63.8%)
Required11 (23.4%)
Privileges Required
Low5 (10.6%)
High0 (0.0%)
None12 (25.5%)
Unknown30 (63.8%)
Top CVEs
Signals from CVEs in this product scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3636MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Sep 6, 2006 | 6.8 | 30 | NO | YES |
CVE-2002-0855HIGH Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw | Sep 5, 2002 | 7.5 | 30 | NO | YES |
CVE-2002-0388HIGH Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries. | Jun 18, 2002 | 7.5 | 30 | NO | YES |
CVE-2021-44227HIGH In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes. | Dec 2, 2021 | 8.8 | 28 | NO | NO |
CVE-2003-0038MEDIUM Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters. | Feb 7, 2003 | 4.3 | 27 | NO | YES |
CVE-2021-42097HIGH GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of a | Oct 21, 2021 | 8.0 | 26 | NO | NO |
CVE-2001-1132HIGH Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during th | Sep 5, 2001 | 7.5 | 25 | NO | NO |
CVE-2025-43920HIGH GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacha | Apr 20, 2025 | 8.1 | 24 | NO | NO |
CVE-2018-13796MEDIUM An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site. | Jul 12, 2018 | 6.5 | 24 | NO | NO |
CVE-2025-43919HIGH GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the privat | Apr 20, 2025 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (47 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
8.5% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (47 CVEs).
Media Mentions
Signals from CVEs in this product scope (47 CVEs).
Top CNAs Publishing CVEs For Mailman
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 1 | 5.1 | 1.9% | 0 | 0 |
| 6.0 | 1 | 5.1 | 1.9% | 0 | 0 |
| 5.1 | 1 | 5.1 | 1.9% | 0 | 0 |
| 5.0 | 1 | 5.1 | 1.9% | 0 | 0 |
| 2.1b1 | 8 | 5.4 | 3.1% | 0 | 1 |
| 2.1.9 | 4 | 5.2 | 2.2% | 0 | 0 |
| 2.1.8 | 6 | 5.5 | 3.0% | 0 | 1 |
| 2.1.7 | 6 | 4.4 | 2.9% | 0 | 1 |
| 2.1.6 | 7 | 5.8 | 3.0% | 0 | 1 |
| 2.1.5.8 | 4 | 5.3 | 4.0% | 0 | 1 |
| 2.1.5 | 10 | 5.6 | 2.9% | 0 | 1 |
| 2.1.4 | 13 | 5.6 | 2.7% | 0 | 1 |
| 2.1.3 | 12 | 5.4 | 2.7% | 0 | 1 |
| 2.1.23 | 1 | 8.8 | 1.6% | 0 | 0 |
| 2.1.22 | 1 | 8.8 | 1.6% | 0 | 0 |
| 2.1.21 | 1 | 8.8 | 1.6% | 0 | 0 |
| 2.1.20 | 1 | 8.8 | 1.6% | 0 | 0 |
| 2.1.2 | 12 | 5.4 | 2.7% | 0 | 1 |
| 2.1.19 | 1 | 8.8 | 1.6% | 0 | 0 |
| 2.1.18-1 | 1 | 8.8 | 1.6% | 0 | 0 |