Mailcleaner is a niche email-filtering and anti-spam appliance that occupies a focused position in the messaging security layer, where its exposure concentrates in a single product line. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, recurrent across weakness classes including OS command injection, cross-site scripting, path traversal, and missing authorization that reflect the parsing and server-side request handling demands of an edge email gateway. Defenders should treat Mailcleaner instances—particularly those internet-exposed—as patching-priority targets; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailcleaner over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20323HIGH www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands. | Mar 21, 2019 | 8.8 | 67 | NO | YES |
CVE-2024-3193HIGH A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoin | Apr 29, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-3191CRITICAL A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The ma | Apr 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-3192CRITICAL A vulnerability, which was classified as problematic, was found in MailCleaner up to 2023.03.14. Affected is an unknown function of the component Admin Interface. The manipulation | Apr 29, 2024 | 9.6 | 23 | NO | NO |
CVE-2019-1010246HIGH MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure. The impact is: MySQL database content di | Jul 18, 2019 | 7.5 | 23 | NO | NO |
CVE-2024-3195HIGH A vulnerability was found in MailCleaner up to 2023.03.14. It has been classified as critical. This affects an unknown part of the component Admin Endpoints. The manipulation leads | Apr 29, 2024 | 7.2 | 21 | NO | NO |
CVE-2018-18635MEDIUM www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allows XSS via the admin/login/user/message/ P | Oct 24, 2018 | 6.1 | 21 | NO | NO |
CVE-2024-3196MEDIUM A vulnerability was found in MailCleaner up to 2023.03.14. It has been declared as critical. This vulnerability affects the function getStats/Services_silentDump/Services_stopStart | Apr 29, 2024 | 6.7 | 19 | NO | NO |
CVE-2024-3194MEDIUM A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some unknown functionality of the component Log File Endpoint. Th | Apr 29, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailcleaner.
Media articles that mention a CVE ID that affects a product developed by Mailcleaner — matched by CVE ID, not by vendor name.