Vimbadmin is a narrowly scoped mail server administration platform whose vulnerability profile centers on web-application input-handling and session-management weaknesses, particularly cross-site scripting and cross-site request forgery. The recurring exposure reflects the web-facing nature of administrative interfaces and the input-validation demands of a management application. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vimbadmin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6086HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to hijack the authentication of log | Jun 27, 2017 | 8.8 | 39 | NO | YES |
CVE-2017-5870MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter | May 23, 2017 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vimbadmin.
Media articles that mention a CVE ID that affects a product developed by Vimbadmin — matched by CVE ID, not by vendor name.