CVE-2019-0218: Apache Pony Mail

Medium severity, CVSS 6.1. EPSS: 5.1% chance of exploitation in the next 30 days.

A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

Affected products

  • Apache Pony Mail: from 0.8, up to and including 0.10

Published 2019-04-22. Last modified 2026-06-17.