Home/Product/modoboa
Product

modoboa

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-27602
< 2.7.1
Modoboa is a mail hosting and management platform. Prior to version 2.7.1, exec_cmd() in modoboa/lib/sysutils.py always runs s
7.2HIGH
CVE-2023-5690
< 2.2.2
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.
8.8HIGH
CVE-2023-5689
< 2.2.2
Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.
5.4MEDIUM
CVE-2023-5688
< 2.2.2
Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.
5.4MEDIUM
CVE-2023-2228
< 2.1.0
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.
6.8MEDIUM
CVE-2023-2227
< 2.1.0
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
9.1CRITICAL
CVE-2023-2160
< 2.1.0
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
6.3MEDIUM
CVE-2023-0949
< 2.0.5
Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5.
4.8MEDIUM
CVE-2023-0860
< 2.0.4
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
7.5HIGH
CVE-2023-0777
< 2.0.4
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
9.8CRITICAL
CVE-2023-0519
< 2.0.4
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
5.4MEDIUM
CVE-2023-0470
< 2.0.4
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
5.4MEDIUM
CVE-2023-0438
< 2.0.4
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
6.5MEDIUM
CVE-2023-0406
< 2.0.4
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
4.3MEDIUM
CVE-2023-0398
< 2.0.4
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
6.5MEDIUM
CVE-2019-19702
all versions
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data
7.5HIGH
threatengine.sh