Vulnerabilities > Rumble Mail Server Project

DATE CVE VULNERABILITY TITLE RISK
2022-04-04 CVE-2021-43459 Cross-site Scripting vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters.
network
low complexity
rumble-mail-server-project CWE-79
5.4
2022-04-04 CVE-2021-43461 Cross-site Scripting vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
network
low complexity
rumble-mail-server-project CWE-79
5.4
2022-04-04 CVE-2021-43462 Cross-site Scripting vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
network
low complexity
rumble-mail-server-project CWE-79
5.4
2022-04-04 CVE-2021-43456 Unquoted Search Path or Element vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.
local
low complexity
rumble-mail-server-project CWE-428
7.8