Hivemail is a narrowly scoped email platform with a small but notable vulnerability footprint concentrated in its core product. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of email systems as a target for attack tooling and integration into broader exploitation chains. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hivemail over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0757HIGH Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update. | Feb 18, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-0759HIGH Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.upda | Feb 18, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0758MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the qu | Feb 18, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-3565HIGH SQL injection vulnerability in search.results.php in HiveMail 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the fields[] parameter. | Jul 13, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-3566MEDIUM search.results.php in HiveMail 3.1 and earlier allows remote attackers to obtain the installation path via certain manipulations related to the (1) searchdate and (2) folderids par | Jul 13, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3564MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the email, (2) cond, or (3) na | Jul 13, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hivemail.
Media articles that mention a CVE ID that affects a product developed by Hivemail — matched by CVE ID, not by vendor name.