โ† All reports

The mailcow-dockerized email suite has multiple security vulnerabilities in versions prior to 2026-03b, including lack of administrator verification, HTML/JS injection, SQL injection, and improper rendering of user data.

CybersecurityTechnologyConflictOpen Source SecurityApr 21, 2026score 0.175 posts ยท 0 replies across 1 instances
This thread discusses multiple security vulnerabilities in the mailcow-dockerized email suite, highlighting issues such as lack of administrator verification during deletion, HTML/JS injection, SQL injection, and improper rendering of user data. These vulnerabilities affect versions prior to 2026-03b and pose significant security risks.

Claims

The mailcow-dockerized email suite has multiple security vulnerabilities in versions prior to 2026-03b, including lack of administrator verification, HTML/JS injection, SQL injection, and improper rendering of user data.
Parent: CybersecurityEntity: mailcow-dockerizedImpact: negativeDate: Apr 21, 2026Target: The security of the mailcow-dockerized email suite

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24255 ๐Ÿ“Š Score: 8.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: mailcow-dockerized ๐Ÿข Vendor: mailcow ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quarantine details modal injects attachment filenames into HTML without escaping, allowing arbitrary HTML/JS execution. An attacker can... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24255 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24256 ๐Ÿ“Š Score: 6.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: mailcow-dockerized ๐Ÿข Vendor: mailcow ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place when deleting Forwarding Hosts with `/api/v1/delete/fwdhost`. Any authenticated user can call thi... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24256 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24258 ๐Ÿ“Š Score: 7.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: mailcow-dockerized ๐Ÿข Vendor: mailcow ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24258 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24253 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: mailcow-dockerized ๐Ÿข Vendor: mailcow ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field via the Mailcow API. The /api/v1/add/mailbox endpoint stores q... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24253 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24254 ๐Ÿ“Š Score: 9.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: mailcow-dockerized ๐Ÿข Vendor: mailcow ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs render the EMailAddress value (logged as the "user" field) without HTML escaping. By submitting an ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24254 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24262 ๐Ÿ“Š Score: 2.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: mailcow-dockerized ๐Ÿข Vendor: mailcow ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface passes the raw `$_SERVER['REQUEST_URI']` to Twig as a global template variable and renders it inside a JavaScript... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24262 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability