Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mailenable

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 90
56.3
VTI Score
TOP TARGET

Mailenable is a narrowly scoped email server platform serving small to medium organizations, yet vulnerabilities in its product line have attracted considerable public exploit tooling and recur across its Standard, Professional, and Enterprise editions alongside related IMAP components. The exposure centers on application-layer and system-level input handling, with recurrent weaknesses including cross-site scripting, path traversal, buffer boundary violations, and uncontrolled search-path manipulation that reflect the parsing demands of email protocols and web administration interfaces. While the product line itself is modestly represented in the vulnerability landscape, its prominence among mail-server deployments has established a durable signal of public-exploit availability for its disclosures, elevating the importance of patch tracking relative to raw CVE volume. Defenders should prioritize Mailenable advisories for internet-facing mail infrastructure and treat this vendor's exploitable conditions as requiring prompt remediation; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
90
Total CVEs
More Total CVEs than 99% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mailenable over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
May 8, 2026
77 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (90 CVEs).

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-2278HIGH
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a lon
Jul 18, 20057.280NOYES
CVE-2006-6423HIGH
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1
Dec 12, 200610.079NOYES
CVE-2005-1348HIGH
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorizat
May 2, 20057.575NOYES
CVE-2005-3155HIGH
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
Oct 5, 20057.571NOYES
CVE-2025-44148CRITICAL
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
Jun 3, 20259.865NOYES
CVE-2005-2223MEDIUM
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authenti
Jul 12, 20055.040NONO
CVE-2008-1277HIGH
The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of service (crash) via (1) SEARC
Mar 10, 20089.039NOYES
CVE-2004-2501HIGH
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command str
Dec 31, 20047.539NOYES
CVE-2008-1276HIGH
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execu
Mar 10, 20089.038NOYES
CVE-2007-1301HIGH
Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via
Mar 7, 20079.038NOYES
View all 90 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products90 CVEs
50%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local12 (13.3%)
Network28 (31.1%)
Unknown50 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (44.4%)
High0 (0.0%)
Unknown50 (55.6%)
User Interaction
None20 (22.2%)
Unknown50 (55.6%)
Required20 (22.2%)
Privileges Required
Low15 (16.7%)
High0 (0.0%)
None25 (27.8%)
Unknown50 (55.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (90 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
4.4% of CVEs· 98th percentile
Nuclei
1 CVE
1.1% of CVEs· 95th percentile
ExploitDB
21 CVEs
23.3% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mailenable.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mailenable — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mailenable's Products

View all 3 CNAs →

Top CWEs