This page lists publicly disclosed CVE vulnerabilities affecting coremail coremail_xt (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2018-14503 | Cross-site scripting (XSS) vulnerability in intervalCheck.jsp in Coremail XT 3.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | [email protected] | 6.1 | 0.79% | 2018-08-10 | 2026-06-17 |
| CVE-2018-9330 | register.jsp in Coremail XT3.0 allows stored XSS, as demonstrated by the third form field to a URI under register/, a different vulnerability than CVE-2015-6942. | [email protected] | 5.4 | 0.53% | 2018-04-07 | 2026-06-17 |
| CVE-2015-6942 | Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTML via a hyperlink in a document attachment. | [email protected] | 6.1 | 0.91% | 2017-08-29 | 2026-06-17 |