The Rumble Mail Server Project maintains a specialized, narrowly scoped mail server product that handles email routing and delivery infrastructure; despite its focused scope, the product operates in a mission-critical role where availability and message integrity matter significantly. The recurring vulnerability pattern centers on web-interface input handling, with observed weakness classes including cross-site scripting and improper search-path construction that are characteristic of mail-server administration and web-access components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rumble Mail Server Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43456HIGH An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path. | Apr 4, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-43462MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter. | Apr 4, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-43461MEDIUM Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter. | Apr 4, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-43459MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters. | Apr 4, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rumble Mail Server Project.
Media articles that mention a CVE ID that affects a product developed by Rumble Mail Server Project — matched by CVE ID, not by vendor name.