Mailcow is a self-hosted, open-source email and groupware platform that consolidates mail server, webmail, and administrative functions into a containerized deployment, attracting the attention of security researchers and exploit developers. The vulnerability profile centers on its web-facing components and recurs through input-handling and web-application weaknesses including cross-site scripting, OS command injection, open redirects, and cross-site request forgery, with a notable tendency toward public exploit availability. Defenders deploying Mailcow should prioritize network isolation and input filtering, and track upstream advisories closely; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailcow over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8928HIGH mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF. | May 14, 2017 | 8.8 | 39 | NO | YES |
CVE-2025-25198HIGH mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker | Feb 12, 2025 | 8.8 | 36 | NO | YES |
CVE-2024-30270MEDIUM mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulne | Apr 4, 2024 | 6.2 | 35 | NO | NO |
CVE-2023-26490HIGH mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning the | Mar 4, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-31138HIGH mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, s | Jul 11, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-39258HIGH mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect | Sep 27, 2022 | 8.2 | 27 | NO | NO |
CVE-2024-31204MEDIUM mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulne | Apr 4, 2024 | 6.1 | 25 | NO | NO |
CVE-2023-34108HIGH mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been disc | Jun 7, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-53909HIGH mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notifi | Jul 17, 2025 | 7.2 | 24 | NO | NO |
CVE-2022-31245HIGH mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS | May 20, 2022 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailcow.
Media articles that mention a CVE ID that affects a product developed by Mailcow — matched by CVE ID, not by vendor name.