This page aggregates publicly disclosed CVE and security risk information related to neomail, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2006-2138 | Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter. | [email protected] | 4.3 | 8.85% | 2006-05-02 | 2026-04-16 |
| CVE-2006-0711 | The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled. | [email protected] | 5.0 | 0.65% | 2006-02-15 | 2026-04-16 |
| CVE-2006-0536 | Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. NOTE: some sources say that the affected parameter is "date," but the demonstration URL shows that it is "sort". | [email protected] | 4.3 | 0.61% | 2006-02-04 | 2026-04-16 |