Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations (CWE) associated with Post SMTP, a comprehensive email deliverability and SMTP solution developed by Post SMTP. It aggregates verified security vulnerabilities and configuration weaknesses linked to this specific software product, covering all recorded incidents from its initial release through the present day. The collection includes flaws related to authentication, data exposure, and transport security that have been publicly disclosed or independently verified. Readers can use this resource to track vendor advisories for Post SMTP, understand the specific manifestations of a given weakness class within an email infrastructure context, and look up a product's vulnerability history to assess long-term security maturity. By consolidating these findings, the page provides a clear view of the attack surface associated with the application’s SMTP relay capabilities, email logging features, and mobile application components. This structured overview allows security teams to evaluate risks accurately, prioritize remediation efforts, and monitor patch adoption trends without relying on fragmented reports. The data reflects both critical severity issues and lower-impact configuration errors that may contribute to broader system compromise. Understanding these aggregated weaknesses helps administrators harden their email systems against known exploitation techniques. This resource serves as a factual reference for security auditors, developers, and IT professionals managing email transport layers. It highlights recurring patterns in the product’s security posture and offers context for how specific flaws impact email deliverability and confidentiality. The page does not speculate on unverified claims but focuses solely on documented evidence. Users can compare these findings against industry benchmarks to gauge the overall resilience of the Post SMTP ecosystem. This approach ensures transparency and supports informed decision-making regarding software procurement and maintenance cycles.

Vendor: saadiqbal

CVE IDTitleCVSSSeverityPublished
CVE-2026-3090 Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' CWE-79 7.2 High2026-03-18
CVE-2026-2559 Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite CWE-862 5.3 Medium2026-03-18
CVE-2025-12887 Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update CWE-862 5.4 Medium2025-12-03
CVE-2025-11833 Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure CWE-862 9.8 Critical2025-11-01
CVE-2025-9219 Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update CWE-862 4.3 Medium2025-09-03
CVE-2024-13844 Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter CWE-89 4.9 Medium2025-03-08
CVE-2025-0521 Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2025-02-18
CVE-2024-5207 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection CWE-89 7.2 High2024-05-30
CVE-2023-6875 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API CWE-639 9.8 Critical2024-01-11
CVE-2023-6629 POST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg CWE-79 6.1 Medium2024-01-03
CVE-2023-7027 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device CWE-79 7.2 High2024-01-03
CVE-2021-4422 POST SMTP Mailer <= 2.0.20 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium2023-07-12
CVE-2023-3082 Post SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via Email CWE-79 7.2 High2023-07-12

All 13 known CVE vulnerabilities affecting Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App with full Chinese analysis, references, and POCs where available.