Skip to main content

Vendor/product archive

apache / pony_mail CVEs

Beta · best-effort

4 CVEs tagged to apache / pony_mail2 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-41873

Published Apr 28, 2026

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. Thi…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2019-0218

Published Apr 22, 2019

A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5658

Published Oct 4, 2018

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4460

Published Aug 22, 2017

Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1