Mailvelope is a browser-based email encryption extension that integrates OpenPGP functionality into webmail interfaces, presenting a specialized attack surface centered on cryptographic verification and UI-layer trust. The documented vulnerabilities reflect the inherent challenges of implementing end-to-end encryption in a browser context, clustering around improper certificate validation, cryptographic signature verification flaws, authorization bypasses, and UI-rendering issues that could undermine the security model users expect from the tool. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailvelope over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9149MEDIUM Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and e | Jul 9, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-9150MEDIUM Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or | Jul 9, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-9148MEDIUM Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a valid self-certification. Keys that are ob | Jul 9, 2019 | 4.3 | 17 | NO | NO |
CVE-2019-9147MEDIUM Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's e | Jul 9, 2019 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailvelope.
Media articles that mention a CVE ID that affects a product developed by Mailvelope — matched by CVE ID, not by vendor name.