Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations (CWE) associated with Post SMTP, a comprehensive email deliverability and SMTP solution developed by Post SMTP. It aggregates verified security vulnerabilities and configuration weaknesses linked to this specific software product, covering all recorded incidents from its initial release through the present day. The collection includes flaws related to authentication, data exposure, and transport security that have been publicly disclosed or independently verified. Readers can use this resource to track vendor advisories for Post SMTP, understand the specific manifestations of a given weakness class within an email infrastructure context, and look up a product's vulnerability history to assess long-term security maturity. By consolidating these findings, the page provides a clear view of the attack surface associated with the application’s SMTP relay capabilities, email logging features, and mobile application components. This structured overview allows security teams to evaluate risks accurately, prioritize remediation efforts, and monitor patch adoption trends without relying on fragmented reports. The data reflects both critical severity issues and lower-impact configuration errors that may contribute to broader system compromise. Understanding these aggregated weaknesses helps administrators harden their email systems against known exploitation techniques. This resource serves as a factual reference for security auditors, developers, and IT professionals managing email transport layers. It highlights recurring patterns in the product’s security posture and offers context for how specific flaws impact email deliverability and confidentiality. The page does not speculate on unverified claims but focuses solely on documented evidence. Users can compare these findings against industry benchmarks to gauge the overall resilience of the Post SMTP ecosystem. This approach ensures transparency and supports informed decision-making regarding software procurement and maintenance cycles.

Vendor: saadiqbal

CVE ID Title CVSS Severity Published
CVE-2026-3090 Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' CWE-79 7.2 High 2026-03-18
CVE-2026-2559 Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite CWE-862 5.3 Medium 2026-03-18
CVE-2025-12887 Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update CWE-862 5.4 Medium 2025-12-03
CVE-2025-11833 Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure CWE-862 9.8 Critical 2025-11-01
CVE-2025-9219 Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update CWE-862 4.3 Medium 2025-09-03
CVE-2024-13844 Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter CWE-89 4.9 Medium 2025-03-08
CVE-2025-0521 Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2025-02-18
CVE-2024-5207 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection CWE-89 7.2 High 2024-05-30
CVE-2023-6875 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API CWE-639 9.8 Critical 2024-01-11
CVE-2023-6629 POST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg CWE-79 6.1 Medium 2024-01-03
CVE-2023-7027 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device CWE-79 7.2 High 2024-01-03
CVE-2021-4422 POST SMTP Mailer <= 2.0.20 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium 2023-07-12
CVE-2023-3082 Post SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via Email CWE-79 7.2 High 2023-07-12

All 13 known CVE vulnerabilities affecting Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App with full Chinese analysis, references, and POCs where available.