Spamtitan develops a focused portfolio of email security and web-filtering appliances, including its namesake email gateway and WebTitan web-filtering product, deployed across mid-market organizations seeking threat prevention. The vendor's vulnerability disclosures center on input-handling and injection weaknesses—cross-site scripting, code injection, path traversal, and SQL injection—that are characteristic of gateway appliances with web-based management interfaces and policy-engine complexity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spamtitan over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4640MEDIUM Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fname paramete | Oct 8, 2012 | 4.0 | 34 | NO | YES |
CVE-2011-5149MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) testaddr or (2) testpass | Aug 31, 2012 | 4.3 | 24 | NO | YES |
CVE-2011-4638HIGH Multiple SQL injection vulnerabilities in SpamTitan WebTitan before 3.60 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to login-x.php, and | Oct 8, 2012 | 7.5 | 22 | NO | NO |
CVE-2011-5150MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.07 and possibly earlier allow remote attackers or authenticated users to inject arbitrary web script or HTML via | Aug 31, 2012 | 4.3 | 22 | NO | YES |
CVE-2011-4639MEDIUM The (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to execute arbitrary commands via shell metacharacte | Oct 8, 2012 | 6.5 | 20 | NO | NO |
CVE-2014-2965MEDIUM Cross-site scripting (XSS) vulnerability in auth-settings-x.php in SpamTitan before 6.04 allows remote attackers to inject arbitrary web script or HTML via the sortdir parameter. | Jul 3, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spamtitan.
Media articles that mention a CVE ID that affects a product developed by Spamtitan — matched by CVE ID, not by vendor name.