Known Vulnerabilities for Mail by Nextcloud
Listed below are 8 of the newest known vulnerabilities associated with "Mail" by "Nextcloud".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-48846 json | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a craf... | Not Provided | 2026-05-25 | 2026-05-26 |
| CVE-2026-48843 json | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) saniti... | Not Provided | 2026-05-25 | 2026-05-26 |
| CVE-2026-45007 json | phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthe... | Not Provided | 2026-05-15 | 2026-05-16 |
| CVE-2026-44844 json | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as c... | Not Provided | 2026-05-26 | 2026-05-27 |
| CVE-2026-42185 json | People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a us... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2026-41904 json | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with upda... | Not Provided | 2026-05-07 | 2026-05-07 |
| CVE-2026-41873 json | ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerabilit... | Not Provided | 2026-04-28 | 2026-04-29 |
| CVE-2026-41319 json | MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versi... | Not Provided | 2026-04-24 | 2026-04-25 |
| CVE-2026-41259 json | Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon a... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-40874 json | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator ... | Not Provided | 2026-04-21 | 2026-04-21 |