Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MailEnable — Vulnerabilities & Security Advisories 28

All 28 CVE vulnerabilities found in MailEnable, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability data for MailEnable, a commercial email server solution developed by MailEnable Ltd, focusing on common weakness types and associated tags. The content collects reports of known security flaws, ranging from remote code execution and authentication bypasses to information disclosure and denial of service issues, covering incidents reported and published from 2003 through the present day. By utilizing this resource, users can effectively track a vendor's advisory history to monitor how MailEnable addresses emerging threats over time, gain a deeper understanding of specific weakness classes within the context of email infrastructure security, and lookup a product's comprehensive vulnerability history to assess long-term risk and patch management efficacy. This aggregation serves as a centralized reference point for security analysts, system administrators, and auditors seeking to evaluate the security posture of MailEnable deployments. It consolidates disparate data sources into a single, accessible interface, allowing stakeholders to correlate findings with specific software versions and operating environments. The information provided is intended to support informed decision-making regarding system hardening, update schedules, and incident response planning without replacing professional security assessments.

Vendor: MailEnable

CVE ID Title CVSS Severity Published
CVE-2026-32852 MailEnable < 10.55 Reflected XSS via FreeBusy.aspx StartDate Parameter CWE-79 6.1 - 2026-03-23
CVE-2026-32851 MailEnable < 10.55 Reflected XSS via FreeBusy.aspx StartDate Parameter CWE-79 6.1 - 2026-03-23
CVE-2026-32850 MailEnable < 10.55 Reflected XSS via ManageShares.aspx SelectedIndex Parameter CWE-79 6.1 - 2026-03-23
CVE-2025-34427 MailEnable < 10.54 Cleartext Credential Storage in AUTH.TAB CWE-312 7.8AI High AI 2025-12-10
CVE-2025-34428 MailEnable < 10.54 Cleartext Credential Storage in AUTH.SAV CWE-312 7.8AI High AI 2025-12-10
CVE-2025-34421 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34417 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISO.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34419 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISM.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34416 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIPO.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34422 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIPC.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34418 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIMF.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34424 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIDP.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34423 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIAU.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34420 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIAM.DLL CWE-427 6.7AI Medium AI 2025-12-10
CVE-2025-34425 MailEnable < 10.54 Reflected XSS in WindowContext Parameter of MAI/compose.aspx CWE-79 6.1AI Medium AI 2025-12-09
CVE-2025-34396 MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAINFY.DLL CWE-427 6.5AI Medium AI 2025-12-09
CVE-2025-34408 MailEnable < 10.54 Reflected XSS in Added Parameter of MAI/AddRecipientsResult.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34398 MailEnable < 10.54 Reflected XSS in AddressesBcc Parameter of AddressBook.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34399 MailEnable < 10.54 Reflected XSS in AddressesCc Parameter of AddressBook.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34400 MailEnable < 10.54 Reflected XSS in AddressesTo Parameter of AddressBook.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34409 MailEnable < 10.54 Reflected XSS in Failed Parameter of MAI/AddRecipientsResult.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34401 MailEnable < 10.54 Reflected XSS in FieldBcc Parameter of AddressBook.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34402 MailEnable < 10.54 Reflected XSS in FieldCc Parameter of AddressBook.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34403 MailEnable < 10.54 Reflected XSS in FieldTo Parameter of AddressBook.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34406 MailEnable < 10.54 Reflected XSS in Id Parameter of Mobile/ContactDetails.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34404 MailEnable < 10.54 Reflected XSS in InstanceScope Parameter of CAL/compose.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34397 MailEnable < 10.54 Reflected XSS in Message Parameter of Mobile/Compose.aspx CWE-79 6.1 - 2025-12-09
CVE-2025-34407 MailEnable < 10.54 Reflected XSS in theme Parameter of Statistics.aspx CWE-79 6.1 - 2025-12-09

All 28 known CVE vulnerabilities affecting MailEnable with full Chinese analysis, references, and POCs where available.