axigen records
14 published records for vendor axigen.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-276 Incorrect Default Permissions1
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-31470Proof of concept | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 1axigen · axigen mobile webmail · CWE-79 | Medium6.1 | — | 52.7% | Jun 7, 2022 |
39Monitor | CVE-2023-48974Proof of concept | Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted scriptaxigen · axigen mail server · CWE-79 | Critical9.6 | — | 3.0% | Feb 7, 2024 |
39Monitor | CVE-2023-23566No exploit | A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to aaxigen · axigen mail server · CWE-276 | Critical9.8 | — | 0.9% | Jan 13, 2023 |
36Monitor | CVE-2020-26942No exploit | An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a axigen · axigen mail server · CWE-306 | Critical9.1 | — | 0.5% | Mar 20, 2024 |
36Monitor | CVE-2025-68723Proof of concept | Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface.axigen · axigen mail server · CWE-79 | Critical9.0 | — | 0.3% | Feb 5, 2026 |
35Monitor | CVE-2025-68722Proof of concept | Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interaxigen · axigen mail server · CWE-352 | High8.8 | — | 0.3% | Feb 5, 2026 |
32Monitor | CVE-2025-68721Proof of concept | Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface.axigen · axigen mail server · CWE-284 | High8.1 | — | 0.3% | Feb 5, 2026 |
26Monitor | CVE-2024-28589Proof of concept | An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbiCWE-732 | Medium6.7 | — | 0.3% | Apr 3, 2024 |
24Monitor | CVE-2024-50601No exploit | Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow CWE-79 | Medium6.1 | — | 0.2% | Nov 11, 2024 |
24Monitor | CVE-2023-49101No exploit | WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of miaxigen · axigen mobile webmail · CWE-79 | Medium6.1 | — | 0.2% | Feb 8, 2024 |
21Monitor | CVE-2015-5379No exploit | Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackeaxigen · axigen mail server · CWE-79 | Medium5.4 | — | 1.6% | Oct 23, 2017 |
21Monitor | CVE-2023-40355Proof of concept | Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, alloaxigen · axigen mobile webmail · CWE-79 | Medium5.4 | — | 1.1% | Feb 7, 2024 |
21Monitor | CVE-2025-68643No exploit | Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter.axigen · axigen mail server · CWE-79 | Medium5.4 | — | 0.2% | Feb 5, 2026 |
18Monitor | CVE-2012-2592Proof of concept | Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the axigen · axigen mail server · CWE-79 | Medium4.3 | — | 1.8% | Jun 18, 2014 |
- CVE-2022-3147040Plan
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 1
MediumCVSS 6.1Proof of conceptEPSS 53%axigen · axigen mobile webmailJun 7, 2022
- CVE-2023-4897439Monitor
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script
CriticalCVSS 9.6Proof of conceptEPSS 3%axigen · axigen mail serverFeb 7, 2024
- CVE-2023-2356639Monitor
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to a
CriticalCVSS 9.8No exploitEPSS 1%axigen · axigen mail serverJan 13, 2023
- CVE-2020-2694236Monitor
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a
CriticalCVSS 9.1No exploitEPSS 0%axigen · axigen mail serverMar 20, 2024
- CVE-2025-6872336Monitor
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface.
CriticalCVSS 9.0Proof of conceptEPSS 0%axigen · axigen mail serverFeb 5, 2026
- CVE-2025-6872235Monitor
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin inter
HighCVSS 8.8Proof of conceptEPSS 0%axigen · axigen mail serverFeb 5, 2026
- CVE-2025-6872132Monitor
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface.
HighCVSS 8.1Proof of conceptEPSS 0%axigen · axigen mail serverFeb 5, 2026
- CVE-2024-2858926Monitor
An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbi
MediumCVSS 6.7Proof of conceptEPSS 0%Apr 3, 2024
- CVE-2024-5060124Monitor
Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow
MediumCVSS 6.1No exploitEPSS 0%Nov 11, 2024
- CVE-2023-4910124Monitor
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mi
MediumCVSS 6.1No exploitEPSS 0%axigen · axigen mobile webmailFeb 8, 2024
- CVE-2015-537921Monitor
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attacke
MediumCVSS 5.4No exploitEPSS 2%axigen · axigen mail serverOct 23, 2017
- CVE-2023-4035521Monitor
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allo
MediumCVSS 5.4Proof of conceptEPSS 1%axigen · axigen mobile webmailFeb 7, 2024
- CVE-2025-6864321Monitor
Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter.
MediumCVSS 5.4No exploitEPSS 0%axigen · axigen mail serverFeb 5, 2026
- CVE-2012-259218Monitor
Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3Proof of conceptEPSS 2%axigen · axigen mail serverJun 18, 2014