Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lsoft

First CVE: Jan 1, 1997Active for: 30 yearsTotal CVEs: 10
52.2
VTI Score
TOP TARGET

Lsoft maintains LISTSERV, a widely deployed enterprise mailing-list and message-management platform with a prominent footprint in academic and organizational environments despite its narrow product scope. The vendor's vulnerability disclosures center on application-layer input handling and access-control weaknesses, including cross-site scripting, authorization bypass, and related web-application flaws, and frequently acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1997
29 years ago
Most Recent CVE
Mar 5, 2023
1,237 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-39195MEDIUM
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
Jan 17, 20236.142NOYES
CVE-2019-15501MEDIUM
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
Aug 26, 20196.142NOYES
CVE-2022-40319HIGH
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauth
Jan 17, 20237.537NOYES
CVE-2000-0425HIGH
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
May 3, 200010.037NOYES
CVE-2023-27641MEDIUM
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.
Mar 5, 20236.130NOYES
CVE-2006-1044HIGH
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via u
Mar 7, 20067.523NONO
CVE-2005-1773HIGH
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be
May 31, 20057.520NONO
CVE-2000-0632HIGH
Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.
Jul 17, 20007.520NONO
CVE-1999-0252HIGH
Buffer overflow in listserv allows arbitrary command execution.
Jan 1, 19977.520NONO
CVE-2010-2723MEDIUM
Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this inf
Jul 13, 20104.315NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
40%
60%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (40.0%)
Unknown6 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (40.0%)
High0 (0.0%)
Unknown6 (60.0%)
User Interaction
None1 (10.0%)
Unknown6 (60.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (40.0%)
Unknown6 (60.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
30.0% of CVEs· 98th percentile
ExploitDB
4 CVEs
40.0% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lsoft's Products

View all 1 CNAs →

Top CWEs