Critical Alert 2 Active Exploits Detected Today

CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability →
CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower


← Back to CVE List

CVE-2025-3929NVD

Vulnerability Summary

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
Severity Level
MEDIUM(5.3)
Published Date
Apr 29, 2025
Last Modified
May 12, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software does not neutralize user-controllable input before it is placed in output that is used as a web page.
CVSS v4.0 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone