Known Vulnerabilities for products from Sympa

Listed below are 13 of the newest known vulnerabilities associated with the vendor "Sympa".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-46900 json 7.5 - HIGH 2023-12-31 2024-01-10
CVE-2020-29668 json Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one fro... 3.7 - LOW 2020-12-10 2023-11-07
CVE-2020-26932 json debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas ... 4.3 - MEDIUM 2020-10-10 2022-11-08
CVE-2020-26880 json Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the ... 7.8 - HIGH 2020-10-07 2023-11-07
CVE-2020-10936 json Sympa before 6.2.56 allows privilege escalation. 7.8 - HIGH 2020-05-27 2023-11-07
CVE-2020-9369 json Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and ... 7.5 - HIGH 2020-02-24 2023-11-07
CVE-2018-1000671 json sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "... 6.1 - MEDIUM 2018-09-06 2020-11-09
CVE-2018-1000550 json The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi templa... 9.8 - CRITICAL 2018-06-26 2020-08-04
CVE-2015-1306 json The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers... Not Provided 2015-01-22 2026-05-06
CVE-2012-2352 json The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which ... Not Provided 2012-05-31 2026-04-29
CVE-2008-4476 json sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ tem... Not Provided 2008-10-07 2026-04-23
CVE-2008-1648 json Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed v... Not Provided 2008-04-02 2026-04-23
CVE-2004-1735 json Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated use... Not Provided 2004-08-21 2025-04-03

Known software with vulnerabilities from Sympa

Type Vendor Product Version
ApplicationSympaSympa0.001

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report