Modoboa is a modestly represented, self-hosted mail and collaboration server platform whose vulnerability profile skews toward serious outcomes with an elevated share reaching critical severity. The exposure concentrates in the core server and installer components and recurs through web-application and access-control weakness classes—cross-site request forgery, cross-site scripting, authentication bypass, improper authorization, and OS command injection—that are characteristic of web-facing mail infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Modoboa over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2227CRITICAL Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0. | Apr 21, 2023 | 9.1 | 66 | NO | YES |
CVE-2023-0777CRITICAL Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | Feb 10, 2023 | 9.8 | 50 | NO | YES |
CVE-2026-56780HIGH Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any | Jun 29, 2026 | 7.5 | 32 | NO | NO |
CVE-2023-2160CRITICAL Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
| Apr 18, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-27602HIGH Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls with `shell=True`. Since domain na | Mar 25, 2026 | 7.2 | 25 | NO | NO |
CVE-2023-5690HIGH Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2. | Oct 20, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-0860HIGH Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4. | Feb 16, 2023 | 7.5 | 24 | NO | NO |
CVE-2019-19702HIGH The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform | Dec 10, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-2228MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0. | Apr 21, 2023 | 6.8 | 22 | NO | NO |
CVE-2023-0398MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. | Jan 19, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Modoboa.
Media articles that mention a CVE ID that affects a product developed by Modoboa — matched by CVE ID, not by vendor name.