| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-4162 | Gravity SMTP <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall | RocketGenius | Gravity SMTP | High | 7.1 | 2026-04-10 09:25:56 | Deep Dive |
| CVE-2026-4020 | Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API | RocketGenius | Gravity SMTP | High | 7.5 | 2026-03-31 01:24:57 | Deep Dive |
| CVE-2026-32538 | WordPress SMTP Mailer plugin <= 1.1.24 - Sensitive Data Exposure vulnerability | Noor Alam | SMTP Mailer | 中危 | - | 2026-03-25 16:15:11 | Deep Dive |
| CVE-2026-32519 | WordPress Bit SMTP plugin <= 1.2.2 - Broken Authentication vulnerability | Bit Apps | Bit SMTP | 中危 | - | 2026-03-25 16:15:07 | Deep Dive |
| CVE-2026-3090 | Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | High | 7.2 | 2026-03-18 15:28:29 | Deep Dive |
| CVE-2026-2559 | Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | Medium | 5.3 | 2026-03-18 15:28:28 | Deep Dive |
| CVE-2021-47870 | GetSimple CMS My SMTP Contact Plugin 1.1.2 - Stored XSS | GetSimple CMS | My SMTP Contact Plugin | - | - | 2026-01-21 17:32:09 | Deep Dive |
| CVE-2021-47778 | GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection | Get-Simple | My SMTP Contact Plugin | - | - | 2026-01-21 17:29:48 | Deep Dive |
| CVE-2021-47830 | GetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF | GetSimple CMS | My SMTP Contact Plugin | - | - | 2026-01-21 17:27:34 | Deep Dive |
| CVE-2025-62123 | WordPress WP Gmail SMTP plugin <= 1.0.7 - Cross Site Request Forgery (CSRF) vulnerability | inkthemes | WP Gmail SMTP | Medium | 4.3 | 2025-12-31 16:26:36 | Deep Dive |
| CVE-2025-62762 | WordPress SMTP Mail plugin <= 1.3.51 - Cross Site Request Forgery (CSRF) vulnerability | photoboxone | SMTP Mail | Medium | 4.3 | 2025-12-09 14:52:23 | Deep Dive |
| CVE-2025-67563 | WordPress Post SMTP plugin <= 3.6.1 - Broken Access Control vulnerability | Saad Iqbal | Post SMTP | Medium | 5.3 | 2025-12-09 14:14:11 | Deep Dive |
| CVE-2025-12887 | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | Medium | 5.4 | 2025-12-03 12:29:54 | Deep Dive |
| CVE-2025-13516 | SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File Upload | brainstormforce | SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers | High | 8.1 | 2025-12-02 08:24:55 | Deep Dive |
| CVE-2025-11833 | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | Critical | 9.8 | 2025-11-01 03:34:36 | Deep Dive |
| CVE-2025-53232 | WordPress WP Gmail SMTP plugin <= 1.0.7 - Sensitive Data Exposure vulnerability | inkthemes | WP Gmail SMTP | - | - | 2025-10-22 14:32:29 | Deep Dive |
| CVE-2025-57992 | WordPress Mail Baby SMTP plugin <= 2.8 - Cross Site Request Forgery (CSRF) vulnerability | InterServer | Mail Baby SMTP | Medium | 4.3 | 2025-09-22 18:24:21 | Deep Dive |
| CVE-2025-9219 | Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | Medium | 4.3 | 2025-09-03 08:27:23 | Deep Dive |
| CVE-2025-48327 | WordPress WP Mailgun SMTP plugin <= 1.0.7 - Broken Access Control vulnerability | inkthemes | WP Mailgun SMTP | Medium | 5.3 | 2025-08-28 12:37:01 | Deep Dive |
| CVE-2025-24000 | WordPress Post SMTP plugin <= 3.2.0 - Account Takeover Vulnerability | Saad Iqbal | Post SMTP | High | 8.8 | 2025-08-07 16:58:29 | Deep Dive |