Postfixadmin is a web-based administration interface for Postfix mail servers, and its vulnerability profile centers on a single, narrowly scoped product where the durable signal reflects application-layer authorization gaps. The observed weakness class of missing authorization is characteristic of administrative interfaces where access controls protect sensitive mail-system configuration and user-management functions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postfixadmin Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a mi | Mar 20, 2017 | 2.7 | 28 | NO | YES |
CVE-2012-0812MEDIUM PostfixAdmin 2.3.4 has multiple XSS vulnerabilities | Nov 22, 2019 | 6.1 | 21 | NO | NO |
CVE-2014-2655MEDIUM SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbit | Apr 2, 2014 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postfixadmin Project.
Media articles that mention a CVE ID that affects a product developed by Postfixadmin Project — matched by CVE ID, not by vendor name.