Openfind maintains a focused portfolio of email and messaging appliances—Mail2000, MailAudit, and MailGates—that handle sensitive organizational communications and sit on the network perimeter. Vulnerabilities affecting these products recur through input-handling and command-injection weakness classes, spanning cross-site scripting, OS command injection, and improper permission assignment, reflecting the parsing and system-integration demands of email infrastructure. A meaningful share of these vulnerabilities reach serious severity; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openfind over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12782CRITICAL Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized acce | Jun 23, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-25849HIGH MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s ac | Nov 1, 2020 | 8.8 | 27 | NO | NO |
CVE-2024-5400HIGH Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands | May 27, 2024 | 8.8 | 26 | NO | NO |
CVE-2020-12776HIGH Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie. | Sep 1, 2020 | 7.2 | 24 | NO | NO |
CVE-2024-5399HIGH Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system co | May 27, 2024 | 7.2 | 22 | NO | NO |
CVE-2019-15073MEDIUM An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects | Nov 20, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-15072MEDIUM The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any paramete | Nov 20, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-15071MEDIUM The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without aut | Nov 20, 2019 | 6.1 | 20 | NO | NO |
CVE-2024-6740MEDIUM Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross- | Jul 15, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-28705MEDIUM Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing | Jun 2, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openfind.
Media articles that mention a CVE ID that affects a product developed by Openfind — matched by CVE ID, not by vendor name.