Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

modoboa — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting modoboa. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Modoboa serves as a comprehensive open-source mail server solution with web administration capabilities, primarily used for managing email services and domains. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting attacks, and privilege escalation flaws, accounting for its 15 recorded CVEs. Notable security characteristics include its modular architecture, which while offering flexibility, has introduced attack surfaces through plugins. A significant incident involved authentication bypass vulnerabilities in versions prior to 2.0.0, allowing unauthorized access to administrative functions. Regular security updates are recommended to mitigate risks associated with its complex permission model and third-party extensions.

CVE IDTitleCVSSSeverityPublished
CVE-2026-27602 Modoboa has an OS Command Injection — modoboaCWE-78 7.2 High2026-03-25
CVE-2023-5690 Cross-Site Request Forgery (CSRF) in modoboa/modoboa — modoboa/modoboaCWE-352 6.5 -2023-10-20
CVE-2023-5689 Cross-site Scripting (XSS) - DOM in modoboa/modoboa — modoboa/modoboaCWE-79 5.4 -2023-10-20
CVE-2023-5688 Cross-site Scripting (XSS) - DOM in modoboa/modoboa — modoboa/modoboaCWE-79 5.4 -2023-10-20
CVE-2023-2228 Cross-Site Request Forgery (CSRF) in modoboa/modoboa — modoboa/modoboaCWE-352 6.5 -2023-04-21
CVE-2023-2227 Improper Authorization in modoboa/modoboa — modoboa/modoboaCWE-285 5.4 -2023-04-21
CVE-2023-2160 Weak Password Requirements in modoboa/modoboa — modoboa/modoboaCWE-521 6.3 Medium2023-04-18
CVE-2023-0949 Cross-site Scripting (XSS) - Reflected in modoboa/modoboa — modoboa/modoboaCWE-79 6.1 -2023-02-22
CVE-2023-0860 Improper Restriction of Excessive Authentication Attempts in modoboa/modoboa-installer — modoboa/modoboa-installerCWE-307 9.1 -2023-02-16
CVE-2023-0777 Authentication Bypass by Primary Weakness in modoboa/modoboa — modoboa/modoboaCWE-305 9.8 -2023-02-10
CVE-2023-0470 Cross-site Scripting (XSS) - Stored in modoboa/modoboa — modoboa/modoboaCWE-79 5.4 -2023-01-26
CVE-2023-0519 Cross-site Scripting (XSS) - Stored in modoboa/modoboa — modoboa/modoboaCWE-79 5.4 -2023-01-26
CVE-2023-0438 Cross-Site Request Forgery (CSRF) in modoboa/modoboa — modoboa/modoboaCWE-352 6.5 -2023-01-23
CVE-2023-0398 Cross-Site Request Forgery (CSRF) in modoboa/modoboa — modoboa/modoboaCWE-352 6.5 -2023-01-19
CVE-2023-0406 Cross-Site Request Forgery (CSRF) in modoboa/modoboa — modoboa/modoboaCWE-352 6.5 -2023-01-19

This page lists every published CVE security advisory associated with modoboa. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.