V Webmail is a narrowly focused email application that, despite its modest disclosure volume, occupies a notable position in the vulnerability landscape relative to its product scope. The vendor's reported vulnerabilities center on its single webmail product, though specific weakness classes have not emerged as a durable pattern. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by V Webmail over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2665HIGH PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir | May 30, 2006 | 7.5 | 33 | NO | YES |
CVE-2006-2666HIGH PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG | May 30, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-0792MEDIUM Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter. NOT | Feb 19, 2006 | 4.3 | 21 | NO | YES |
CVE-2008-3063HIGH SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter. | Oct 8, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-3060MEDIUM V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which re | Oct 8, 2008 | 5.0 | 15 | NO | NO |
CVE-2006-0793MEDIUM frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter. NOTE: the provenance of this informa | Feb 19, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-0794MEDIUM help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters. NOTE: the provenance of this information is unknown; the de | Feb 19, 2006 | 5.0 | 15 | NO | NO |
CVE-2008-3061MEDIUM Open redirect vulnerability in redirect.php in V-webmail 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the to par | Oct 8, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by V Webmail.
Media articles that mention a CVE ID that affects a product developed by V Webmail — matched by CVE ID, not by vendor name.