Mailstore develops email archiving and compliance software centered on its Mailstore Server product, a niche offering targeting organizations with retention and legal-discovery requirements. The recurring vulnerability signal reflects the product's role handling certificate validation and session management in a mail-processing context, with observed weaknesses in certificate validation and session-expiration controls. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailstore over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10229HIGH An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the directory service (for synchronizing and authenticating users) i | Dec 31, 2019 | 8.8 | 26 | NO | NO |
CVE-2020-11806MEDIUM In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server. | Apr 23, 2020 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailstore.
Media articles that mention a CVE ID that affects a product developed by Mailstore — matched by CVE ID, not by vendor name.