Mailtraq is a niche email and messaging platform whose vulnerability profile centers on web-facing components including its webmail interface, with the recurring signal focused on input-handling weaknesses such as cross-site scripting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailtraq over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2586MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a J | Sep 19, 2012 | 4.3 | 24 | NO | YES |
CVE-2019-9558MEDIUM Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exploit the vulnerability, the victim must open an email with m | Mar 12, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailtraq.
Media articles that mention a CVE ID that affects a product developed by Mailtraq — matched by CVE ID, not by vendor name.