Skip to content
Noroxi

axigen records

14 published records for vendor axigen.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

14 records
  • An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 1

    MediumCVSS 6.1Proof of conceptEPSS 53%

    axigen · axigen mobile webmailJun 7, 2022

  • Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script

    CriticalCVSS 9.6Proof of conceptEPSS 3%

    axigen · axigen mail serverFeb 7, 2024

  • A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to a

    CriticalCVSS 9.8No exploitEPSS 1%

    axigen · axigen mail serverJan 13, 2023

  • An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a

    CriticalCVSS 9.1No exploitEPSS 0%

    axigen · axigen mail serverMar 20, 2024

  • Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface.

    CriticalCVSS 9.0Proof of conceptEPSS 0%

    axigen · axigen mail serverFeb 5, 2026

  • Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin inter

    HighCVSS 8.8Proof of conceptEPSS 0%

    axigen · axigen mail serverFeb 5, 2026

  • Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface.

    HighCVSS 8.1Proof of conceptEPSS 0%

    axigen · axigen mail serverFeb 5, 2026

  • An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbi

    MediumCVSS 6.7Proof of conceptEPSS 0%

    Apr 3, 2024

  • Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow

    MediumCVSS 6.1No exploitEPSS 0%

    Nov 11, 2024

  • WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mi

    MediumCVSS 6.1No exploitEPSS 0%

    axigen · axigen mobile webmailFeb 8, 2024

  • CVE-2015-5379
    21Monitor

    Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attacke

    MediumCVSS 5.4No exploitEPSS 2%

    axigen · axigen mail serverOct 23, 2017

  • Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allo

    MediumCVSS 5.4Proof of conceptEPSS 1%

    axigen · axigen mobile webmailFeb 7, 2024

  • Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter.

    MediumCVSS 5.4No exploitEPSS 0%

    axigen · axigen mail serverFeb 5, 2026

  • CVE-2012-2592
    18Monitor

    Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the

    MediumCVSS 4.3Proof of conceptEPSS 2%

    axigen · axigen mail serverJun 18, 2014