Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MailEssentials AI — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in MailEssentials AI, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities for the MailEssentials AI product, a Microsoft Exchange and Office 365 email filtering solution by Kerio Technologies. It aggregates security weaknesses categorized under common weakness enumerations, focusing on issues that impact email integrity, privacy, and server stability. The content covers vulnerability reports published from 2020 through the current year, ensuring a comprehensive view of both historical and recent security findings. Visitors can use this resource to track specific vendor advisories released by Kerio Technologies and its parent company, Imperva, to stay informed about ongoing threat mitigation efforts. Users may also explore the technical details of specific weakness classes, such as cross-site scripting or injection flaws, to understand the underlying security mechanisms and potential attack vectors associated with these categories. Additionally, the page provides a historical timeline of a product's vulnerability profile, allowing security professionals and administrators to assess the maturity of the software's security posture over time. This structured approach helps in evaluating risk, planning patch deployment strategies, and ensuring compliance with internal security policies. By centralizing this information, the page serves as a single point of reference for understanding the security landscape of MailEssentials AI, facilitating better decision-making for enterprise IT teams responsible for maintaining secure email infrastructure.

Vendor: GFI Software

CVE IDTitleCVSSSeverityPublished
CVE-2026-23621 GFI MailEssentials AI < 22.4 ListServer.IsPathExist() Absolute Directory Traversal to File Enumeration CWE-203 4.3 Medium2026-02-19
CVE-2026-23620 GFI MailEssentials AI < 22.4 ListServer.IsDBExist() Absolute Directory Traversal to File Enumeration CWE-203 4.3 Medium2026-02-19
CVE-2026-23619 GFI MailEssentials AI < 22.4 General Settings Local Domains Domain Description Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23618 GFI MailEssentials AI < 22.4 Anti-Spam Spam Keyword Checking Subject Condition Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23617 GFI MailEssentials AI < 22.4 Anti-Spam Spam Keyword Checking Body Condition Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23616 GFI MailEssentials AI < 22.4 Anti-Spam Anti-Spoofing Description Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23615 GFI MailEssentials AI < 22.4 Anti-Spam Sender Policy Framework Email Exceptions Description Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23614 GFI MailEssentials AI < 22.4 Anti-Spam Sender Policy Framework IP Exceptions Description Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23613 GFI MailEssentials AI < 22.4 Anti-Spam URI DNS Blocklist Domain Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23612 GFI MailEssentials AI < 22.4 Anti-Spam IP DNS Blocklist Domain Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23611 GFI MailEssentials AI < 22.4 Anti-Spam IP Blocklist Description Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23610 GFI MailEssentials AI < 22.4 POP2Exchange POP3 Server Login Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23609 GFI MailEssentials AI < 22.4 General Settings Perimeter SMTP Servers Description Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23608 GFI MailEssentials AI < 22.4 Email Management Mail Monitoring Rule Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23607 GFI MailEssentials AI < 22.4 Anti-Spam Whitelist Description Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23606 GFI MailEssentials AI < 22.4 Advanced Content Filtering Rule Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23605 GFI MailEssentials AI < 22.4 Attachment Filtering Rule Stored XSS CWE-79 5.4 Medium2026-02-19
CVE-2026-23604 GFI MailEssentials AI < 22.4 Keyword Filtering Rule Stored XSS CWE-79 5.4 Medium2026-02-19

All 18 known CVE vulnerabilities affecting MailEssentials AI with full Chinese analysis, references, and POCs where available.