SEPPmail records
26 published records for vendor seppmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-295 Improper Certificate Validation2
- CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-347 Improper Verification of Cryptographic Signature2
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-2743No exploit | SEPPmail User Web Interface Arbitrary File Write to RCEseppmail · seppmail · CWE-22 | Critical10.0 | — | 1.0% | Mar 5, 2026 |
38Monitor | CVE-2026-27441No exploit | SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.seppmail · seppmail · CWE-78 | Critical9.5 | — | 0.5% | Mar 4, 2026 |
37Monitor | CVE-2026-27442No exploit | zip_attachments Path Traversalseppmail · seppmail · CWE-22 | Critical9.3 | — | 0.5% | Mar 4, 2026 |
35Monitor | CVE-2022-41871No exploit | SEPPmail through 12.1.17 allows command injection within the Admin Portal.seppmail · seppmail · CWE-78 | High8.8 | — | 1.1% | Apr 28, 2025 |
32Monitor | CVE-2026-27443No exploit | S/MIME Decryption Tag Sanitization Bypassseppmail · seppmail · CWE-20 | High8.2 | — | 0.4% | Mar 4, 2026 |
31Monitor | CVE-2026-29139No exploit | GINA State Confusion Account Takeoverseppmail · secure email gateway · CWE-288 | High7.8 | — | 0.5% | Apr 2, 2026 |
31Monitor | CVE-2026-29143No exploit | S/MIME Decryption Impersonationseppmail · secure email gateway · CWE-20 | High7.8 | — | 0.4% | Apr 2, 2026 |
31Monitor | CVE-2026-27444No exploit | Header Email Address Parsingseppmail · seppmail · CWE-436 | High7.8 | — | 0.4% | Mar 4, 2026 |
31Monitor | CVE-2026-29144No exploit | Unicode Subject Tagsseppmail · secure email gateway · CWE-20 | High7.8 | — | 0.3% | Apr 2, 2026 |
31Monitor | CVE-2026-2748No exploit | S/MIME Certificate Subject Whitespaceseppmail · seppmail · CWE-295 | High7.8 | — | 0.2% | Mar 4, 2026 |
30Monitor | CVE-2026-29141No exploit | Bounded Subject Tag Sanitizationseppmail · secure email gateway · CWE-20 | High7.7 | — | 0.3% | Apr 2, 2026 |
30Monitor | CVE-2026-29140No exploit | S/MIME Signature Additional Certificateseppmail · secure email gateway · CWE-295 | High7.7 | — | 0.2% | Apr 2, 2026 |
27Monitor | CVE-2026-2747No exploit | PGP Mixed Plaintext and Encrypted Contentseppmail · seppmail · CWE-200 | Medium6.9 | — | 0.4% | Mar 4, 2026 |
27Monitor | CVE-2026-27445No exploit | PGP Signature Reflectionseppmail · seppmail · CWE-347 | Medium6.9 | — | 0.2% | Mar 4, 2026 |
27Monitor | CVE-2026-2746No exploit | Missing PGP Signature Tagseppmail · seppmail · CWE-347 | Medium6.9 | — | 0.2% | Mar 4, 2026 |
25Monitor | CVE-2026-29132No exploit | ESWmail-Verify Bypassseppmail · secure email gateway · CWE-306 | Medium6.3 | — | 0.4% | Apr 2, 2026 |
25Monitor | CVE-2026-29138No exploit | PGP Decryption Sender LDAP Injectionseppmail · secure email gateway · CWE-90 | Medium6.3 | — | 0.4% | Apr 2, 2026 |
25Monitor | CVE-2026-29142No exploit | Plaintext secure-mail.htmlseppmail · secure email gateway · CWE-325 | Medium6.3 | — | 0.2% | Apr 2, 2026 |
24Monitor | CVE-2021-31739No exploit | The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attriseppmail · seppmail · CWE-79 | Medium6.1 | — | 0.4% | Nov 18, 2022 |
24Monitor | CVE-2021-31740No exploit | SEPPMail's web frontend, user input is not embedded correctly in the web page and therefore leads to cross-site scripting vulnerabilities (Xseppmail · seppmail · CWE-79 | Medium6.1 | — | 0.4% | Nov 30, 2022 |
21Monitor | CVE-2026-29135No exploit | Webmail Password Tag Sanitization Bypassseppmail · secure email gateway · CWE-20 | Medium5.3 | — | 0.4% | Apr 2, 2026 |
21Monitor | CVE-2026-29133No exploit | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.seppmail · secure email gateway · CWE-20 | Medium5.3 | — | 0.4% | Apr 2, 2026 |
21Monitor | CVE-2026-29134No exploit | SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictseppmail · secure email gateway · CWE-807 | Medium5.3 | — | 0.4% | Apr 2, 2026 |
21Monitor | CVE-2026-29137No exploit | Long Subject Untaggingseppmail · secure email gateway · CWE-20 | Medium5.3 | — | 0.3% | Apr 2, 2026 |
21Monitor | CVE-2026-29136No exploit | CA Notification HTML Injectionseppmail · secure email gateway · CWE-79 | Medium5.3 | — | 0.2% | Apr 2, 2026 |
- CVE-2026-274340Plan
SEPPmail User Web Interface Arbitrary File Write to RCE
CriticalCVSS 10.0No exploitEPSS 1%seppmail · seppmailMar 5, 2026
- CVE-2026-2744138Monitor
SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.
CriticalCVSS 9.5No exploitEPSS 1%seppmail · seppmailMar 4, 2026
- CVE-2026-2744237Monitor
zip_attachments Path Traversal
CriticalCVSS 9.3No exploitEPSS 0%seppmail · seppmailMar 4, 2026
- CVE-2022-4187135Monitor
SEPPmail through 12.1.17 allows command injection within the Admin Portal.
HighCVSS 8.8No exploitEPSS 1%seppmail · seppmailApr 28, 2025
- CVE-2026-2744332Monitor
S/MIME Decryption Tag Sanitization Bypass
HighCVSS 8.2No exploitEPSS 0%seppmail · seppmailMar 4, 2026
- CVE-2026-2913931Monitor
GINA State Confusion Account Takeover
HighCVSS 7.8No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2914331Monitor
S/MIME Decryption Impersonation
HighCVSS 7.8No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2744431Monitor
Header Email Address Parsing
HighCVSS 7.8No exploitEPSS 0%seppmail · seppmailMar 4, 2026
- CVE-2026-2914431Monitor
Unicode Subject Tags
HighCVSS 7.8No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-274831Monitor
S/MIME Certificate Subject Whitespace
HighCVSS 7.8No exploitEPSS 0%seppmail · seppmailMar 4, 2026
- CVE-2026-2914130Monitor
Bounded Subject Tag Sanitization
HighCVSS 7.7No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2914030Monitor
S/MIME Signature Additional Certificate
HighCVSS 7.7No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-274727Monitor
PGP Mixed Plaintext and Encrypted Content
MediumCVSS 6.9No exploitEPSS 0%seppmail · seppmailMar 4, 2026
- CVE-2026-2744527Monitor
PGP Signature Reflection
MediumCVSS 6.9No exploitEPSS 0%seppmail · seppmailMar 4, 2026
- CVE-2026-274627Monitor
Missing PGP Signature Tag
MediumCVSS 6.9No exploitEPSS 0%seppmail · seppmailMar 4, 2026
- CVE-2026-2913225Monitor
ESWmail-Verify Bypass
MediumCVSS 6.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2913825Monitor
PGP Decryption Sender LDAP Injection
MediumCVSS 6.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2914225Monitor
Plaintext secure-mail.html
MediumCVSS 6.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2021-3173924Monitor
The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attri
MediumCVSS 6.1No exploitEPSS 0%seppmail · seppmailNov 18, 2022
- CVE-2021-3174024Monitor
SEPPMail's web frontend, user input is not embedded correctly in the web page and therefore leads to cross-site scripting vulnerabilities (X
MediumCVSS 6.1No exploitEPSS 0%seppmail · seppmailNov 30, 2022
- CVE-2026-2913521Monitor
Webmail Password Tag Sanitization Bypass
MediumCVSS 5.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2913321Monitor
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.
MediumCVSS 5.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2913421Monitor
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrict
MediumCVSS 5.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2913721Monitor
Long Subject Untagging
MediumCVSS 5.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026
- CVE-2026-2913621Monitor
CA Notification HTML Injection
MediumCVSS 5.3No exploitEPSS 0%seppmail · secure email gatewayApr 2, 2026