Mailman is a widely used open-source mailing-list management platform deployed across educational institutions, organizations, and community servers. Its vulnerability profile centers on the core mailman product and centers on web-interface input-handling weaknesses, particularly cross-site scripting issues in message processing and web-form components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailman over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0564MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) | Feb 5, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailman.
Media articles that mention a CVE ID that affects a product developed by Mailman — matched by CVE ID, not by vendor name.