Mail Masta Project maintains a focused email-handling application that, despite its narrow product scope, achieves prominence among tracked vulnerability sources in the landscape. The vendor's disclosures cluster around a single product line with no clearly dominant weakness pattern, reflecting typical challenges in email processing and message handling. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mail Masta Project over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6095CRITICAL A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: li | Feb 21, 2017 | 9.8 | 43 | NO | YES |
CVE-2016-10956HIGH The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php. | Sep 16, 2019 | 7.5 | 39 | NO | YES |
CVE-2017-6098HIGH A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) w | Feb 21, 2017 | 7.2 | 36 | NO | YES |
CVE-2017-6097HIGH A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress | Feb 21, 2017 | 7.2 | 36 | NO | YES |
CVE-2017-6096HIGH A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) | Feb 21, 2017 | 7.2 | 36 | NO | YES |
CVE-2017-6578HIGH A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST | Mar 9, 2017 | 7.2 | 23 | NO | NO |
CVE-2017-6577HIGH A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST | Mar 9, 2017 | 7.2 | 23 | NO | NO |
CVE-2017-6573HIGH A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET | Mar 9, 2017 | 7.2 | 23 | NO | NO |
CVE-2017-6571HIGH A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with t | Mar 9, 2017 | 7.2 | 23 | NO | NO |
CVE-2017-6570HIGH A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php w | Mar 9, 2017 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mail Masta Project.
Media articles that mention a CVE ID that affects a product developed by Mail Masta Project — matched by CVE ID, not by vendor name.