Postfix Admin is a web-based administration tool for Postfix mail servers, and its vulnerability profile centers on the application layer with recurring input-handling weaknesses including cross-site scripting and SQL injection. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postfix Admin Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a mi | Mar 20, 2017 | 2.7 | 28 | NO | YES |
CVE-2012-0812MEDIUM PostfixAdmin 2.3.4 has multiple XSS vulnerabilities | Nov 22, 2019 | 6.1 | 21 | NO | NO |
CVE-2014-2655MEDIUM SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbit | Apr 2, 2014 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postfix Admin Project.
Media articles that mention a CVE ID that affects a product developed by Postfix Admin Project — matched by CVE ID, not by vendor name.