Neomail is a focused email or messaging platform with a narrow vulnerability footprint that has been tracked in the landscape. The observed disclosures involve the product itself and have centered on general or miscellaneous weakness patterns; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neomail over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2138MEDIUM Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter. | May 2, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-0711MEDIUM The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files | Feb 15, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-0536MEDIUM Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. NOTE: some sources sa | Feb 4, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neomail.
Media articles that mention a CVE ID that affects a product developed by Neomail — matched by CVE ID, not by vendor name.