Mdaemon operates a focused email and messaging platform with integrated security-gateway functionality, where observed vulnerabilities concentrate around web-interface input handling and cryptographic implementation. The recurring weaknesses—cross-site scripting flaws in web components and inadequate encryption strength—reflect risks inherent to email systems that expose web administrative and user-facing interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mdaemon over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11182MEDIUM An XSS issue was discovered in
MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message
with
JavaScript in an img tag. This could
allow a remot | Nov 15, 2024 | 6.1 | 67 | YES | NO |
CVE-2025-3929MEDIUM An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could | Apr 29, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-52269MEDIUM MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrato | Dec 31, 2023 | 4.8 | 16 | NO | NO |
CVE-2002-1739MEDIUM Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords. | Dec 31, 2002 | 5.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mdaemon.
Media articles that mention a CVE ID that affects a product developed by Mdaemon — matched by CVE ID, not by vendor name.