Superwebmailer is a narrowly focused web-based email application whose modest vulnerability footprint punches above its apparent size due to an elevated tendency toward critical-severity outcomes and frequent public exploit availability. The recurring exposure centers on input-handling weaknesses across cross-site scripting, code injection, command injection, and SQL injection—a pattern characteristic of web applications that process and render user-supplied content and database queries without adequate sanitization. Defenders should treat this vendor's advisories as high-priority for any deployment and monitor for active tooling; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Superwebmailer over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11546CRITICAL SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit | Jul 14, 2020 | 9.8 | 59 | NO | YES |
CVE-2023-38194MEDIUM An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter. | Oct 21, 2023 | 6.1 | 28 | NO | YES |
CVE-2023-38192MEDIUM An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords. | Oct 21, 2023 | 6.1 | 28 | NO | YES |
CVE-2024-24131MEDIUM SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php. | Feb 7, 2024 | 6.1 | 26 | NO | YES |
CVE-2023-38190HIGH An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter. | Oct 21, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-38193HIGH An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line. | Oct 21, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-38191MEDIUM An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename. | Oct 20, 2023 | 6.1 | 18 | NO | NO |
CVE-2015-2349MEDIUM Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the | Mar 19, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Superwebmailer.
Media articles that mention a CVE ID that affects a product developed by Superwebmailer — matched by CVE ID, not by vendor name.