Mailenable is a narrowly scoped email server platform serving small to medium organizations, yet vulnerabilities in its product line have attracted considerable public exploit tooling and recur across its Standard, Professional, and Enterprise editions alongside related IMAP components. The exposure centers on application-layer and system-level input handling, with recurrent weaknesses including cross-site scripting, path traversal, buffer boundary violations, and uncontrolled search-path manipulation that reflect the parsing demands of email protocols and web administration interfaces. While the product line itself is modestly represented in the vulnerability landscape, its prominence among mail-server deployments has established a durable signal of public-exploit availability for its disclosures, elevating the importance of patch tracking relative to raw CVE volume. Defenders should prioritize Mailenable advisories for internet-facing mail infrastructure and treat this vendor's exploitable conditions as requiring prompt remediation; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailenable over time
Signals from CVEs in this vendor scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2278HIGH Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a lon | Jul 18, 2005 | 7.2 | 80 | NO | YES |
CVE-2006-6423HIGH Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1 | Dec 12, 2006 | 10.0 | 79 | NO | YES |
CVE-2005-1348HIGH Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorizat | May 2, 2005 | 7.5 | 75 | NO | YES |
CVE-2005-3155HIGH Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code. | Oct 5, 2005 | 7.5 | 71 | NO | YES |
CVE-2025-44148CRITICAL Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component | Jun 3, 2025 | 9.8 | 65 | NO | YES |
CVE-2005-2223MEDIUM Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authenti | Jul 12, 2005 | 5.0 | 40 | NO | NO |
CVE-2008-1277HIGH The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of service (crash) via (1) SEARC | Mar 10, 2008 | 9.0 | 39 | NO | YES |
CVE-2004-2501HIGH Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command str | Dec 31, 2004 | 7.5 | 39 | NO | YES |
CVE-2008-1276HIGH Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execu | Mar 10, 2008 | 9.0 | 38 | NO | YES |
CVE-2007-1301HIGH Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via | Mar 7, 2007 | 9.0 | 38 | NO | YES |
Signals from CVEs in this vendor scope (90 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailenable.
Media articles that mention a CVE ID that affects a product developed by Mailenable — matched by CVE ID, not by vendor name.