Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openfind

First CVE: Jun 19, 2019Active for: 7 yearsTotal CVEs: 14
23.5
VTI Score
Low

Openfind maintains a focused portfolio of email and messaging appliances—Mail2000, MailAudit, and MailGates—that handle sensitive organizational communications and sit on the network perimeter. Vulnerabilities affecting these products recur through input-handling and command-injection weakness classes, spanning cross-site scripting, OS command injection, and improper permission assignment, reflecting the parsing and system-integration demands of email infrastructure. A meaningful share of these vulnerabilities reach serious severity; live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openfind over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2019
7 years ago
Most Recent CVE
Jul 15, 2024
743 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-12782CRITICAL
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized acce
Jun 23, 20209.830NONO
CVE-2020-25849HIGH
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s ac
Nov 1, 20208.827NONO
CVE-2024-5400HIGH
Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands
May 27, 20248.826NONO
CVE-2020-12776HIGH
Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie.
Sep 1, 20207.224NONO
CVE-2024-5399HIGH
Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system co
May 27, 20247.222NONO
CVE-2019-15073MEDIUM
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects
Nov 20, 20196.121NONO
CVE-2019-15072MEDIUM
The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any paramete
Nov 20, 20196.120NONO
CVE-2019-15071MEDIUM
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without aut
Nov 20, 20196.120NONO
CVE-2024-6740MEDIUM
Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-
Jul 15, 20246.119NONO
CVE-2023-28705MEDIUM
Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing
Jun 2, 20236.119NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
64%
29%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (42.9%)
Unknown0 (0.0%)
Required8 (57.1%)
Privileges Required
Low3 (21.4%)
High2 (14.3%)
None9 (64.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openfind.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openfind — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openfind's Products

View all 2 CNAs →

Top CWEs