mailman
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mailmanpage 1 of 1
- CVE-2003-0038NONECVSS 0.0EG 0.0✓ Fixed in 2.1.12003-02-07
vulnerable: 3.0.0b3-
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.
- CVE-2004-0412NONECVSS 0.0EG 0.0✓ Fixed in 2.1.52004-08-18
vulnerable: 3.0.0b3-
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
- CVE-2004-1177NONECVSS 0.0EG 0.0✓ Fixed in 2.1.52005-01-10
vulnerable: 3.0.0b3-
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
- CVE-2018-13796MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1.282018-07-12
vulnerable: 3.0.0b3-
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
- CVE-2021-34337MEDIUMCVSS 6.3EG 6.3✓ Fixed in 3.3.52023-04-15
vulnerable: 3.0.0 ... 3.3.5rc1 (43 versions)
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound…
- CVE-2021-44227HIGHCVSS 8.8EG 8.8✓ Fixed in 2.1.382021-12-02
vulnerable: 3.0.0b3-
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
Check whether mailman is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mailman CVEs against the assets you own.
Start Free Scan →