← Back to browse · API

CVE-2025-44148

Severity
CRITICAL
CVSS
9.8
EPSS
0.52631
Risk score
57.62
CISA KEV
No
PoC
No
Published
2025-06-03
Modified
2026-07-05
First seen
2026-08-07
Aliases
EUVD-2025-16734, GHSA-MCVH-WCMH-927V
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-16734

Description

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

References