Lsoft maintains LISTSERV, a widely deployed enterprise mailing-list and message-management platform with a prominent footprint in academic and organizational environments despite its narrow product scope. The vendor's vulnerability disclosures center on application-layer input handling and access-control weaknesses, including cross-site scripting, authorization bypass, and related web-application flaws, and frequently acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lsoft over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39195MEDIUM A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter. | Jan 17, 2023 | 6.1 | 42 | NO | YES |
CVE-2019-15501MEDIUM Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. | Aug 26, 2019 | 6.1 | 42 | NO | YES |
CVE-2022-40319HIGH The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauth | Jan 17, 2023 | 7.5 | 37 | NO | YES |
CVE-2000-0425HIGH Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands. | May 3, 2000 | 10.0 | 37 | NO | YES |
CVE-2023-27641MEDIUM The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL. | Mar 5, 2023 | 6.1 | 30 | NO | YES |
CVE-2006-1044HIGH Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via u | Mar 7, 2006 | 7.5 | 23 | NO | NO |
CVE-2005-1773HIGH Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be | May 31, 2005 | 7.5 | 20 | NO | NO |
CVE-2000-0632HIGH Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string. | Jul 17, 2000 | 7.5 | 20 | NO | NO |
CVE-1999-0252HIGH Buffer overflow in listserv allows arbitrary command execution. | Jan 1, 1997 | 7.5 | 20 | NO | NO |
CVE-2010-2723MEDIUM Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this inf | Jul 13, 2010 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lsoft.
Media articles that mention a CVE ID that affects a product developed by Lsoft — matched by CVE ID, not by vendor name.