altn CVE Vulnerabilities & Metrics

Focus on altn vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About altn Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with altn. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total altn CVEs: 21
Earliest CVE date: 17 Mar 2008, 17:44 UTC
Latest CVE date: 25 Aug 2022, 16:15 UTC

Latest CVE reference: CVE-2022-37238

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical altn CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.24

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 11
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS altn CVEs

These are the five CVEs with the highest CVSS scores for altn, sorted by severity first and recency.

All CVEs for altn

CVE-2022-37238 altn vulnerability CVSS: 0 25 Aug 2022, 16:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.

CVE-2022-37245 altn vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.

CVE-2022-37244 altn vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.

CVE-2022-37243 altn vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.

CVE-2022-37242 altn vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.

CVE-2022-37241 altn vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.

CVE-2022-37240 altn vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.

CVE-2022-37239 altn vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.

CVE-2022-29976 altn vulnerability CVSS: 3.5 11 May 2022, 13:15 UTC

An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .

CVE-2022-29975 altn vulnerability CVSS: 3.5 11 May 2022, 13:15 UTC

An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .

CVE-2021-27183 altn vulnerability CVSS: 6.5 14 Apr 2021, 23:15 UTC

An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new files in any location of the filesystem, or he may be able to modify existing files. This vulnerability may directly lead to Remote Code Execution.

CVE-2021-27182 altn vulnerability CVSS: 6.5 14 Apr 2021, 23:15 UTC

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

CVE-2021-27181 altn vulnerability CVSS: 6.8 14 Apr 2021, 23:15 UTC

An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a malicious URL provided by the attacker and successfully authenticate into the application. Having the value of the anti-CSRF token, the attacker may trick the user into visiting his malicious page and performing any request with the privileges of attacked user.

CVE-2021-27180 altn vulnerability CVSS: 4.3 14 Apr 2021, 23:15 UTC

An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of the attacked user.

CVE-2020-18724 altn vulnerability CVSS: 3.5 03 Feb 2021, 18:15 UTC

Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.

CVE-2020-18723 altn vulnerability CVSS: 3.5 03 Feb 2021, 18:15 UTC

Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.

CVE-2019-19497 altn vulnerability CVSS: 3.5 17 Dec 2019, 19:15 UTC

MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.

CVE-2018-17792 altn vulnerability CVSS: 6.8 19 Jul 2019, 17:15 UTC

MDaemon Webmail (formerly WorldClient) has CSRF.

CVE-2019-13612 altn vulnerability CVSS: 5.0 16 Jul 2019, 13:15 UTC

MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a customer deploys a server with sufficient resources to scan large messages.

CVE-2019-8984 altn vulnerability CVSS: 4.3 21 Feb 2019, 15:29 UTC

MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).

CVE-2019-8983 altn vulnerability CVSS: 4.3 21 Feb 2019, 15:29 UTC

MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).

CVE-2012-2584 altn vulnerability CVSS: 4.3 12 Aug 2012, 17:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a CSS comment within the STYLE attribute of an IMG element, (2) the CSS expression property in conjunction with multiple CSS comments within the STYLE attribute of an arbitrary element, or (3) an innerHTML attribute within an XML document.

CVE-2008-2631 altn vulnerability CVSS: 5.0 10 Jun 2008, 00:32 UTC

The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted HTTP POST request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2008-1358 altn vulnerability CVSS: 6.5 17 Mar 2008, 17:44 UTC

Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY.