CVE-2016-7123: GNU Mailman

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.

Affected products

  • GNU Mailman: up to and including 2.1.14

Published 2016-09-02. Last modified 2026-06-17.