Vulnerabilities > Rumble Mail Server Project

DATE CVE VULNERABILITY TITLE RISK
2022-04-04 CVE-2021-43459 Cross-site Scripting vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters.
3.5
2022-04-04 CVE-2021-43461 Cross-site Scripting vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
3.5
2022-04-04 CVE-2021-43462 Cross-site Scripting vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
network
low complexity
rumble-mail-server-project CWE-79
5.4
2022-04-04 CVE-2021-43456 Unquoted Search Path or Element vulnerability in Rumble Mail Server Project Rumble Mail Server 0.51.3135
An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.
local
low complexity
rumble-mail-server-project CWE-428
7.8