CVE-2019-19129: Afterlogic Aurora
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.
Affected products
- Afterlogic Aurora: version 8.3.11 only
- Afterlogic Webmail Pro: version 8.3.11 only
Published 2019-11-26. Last modified 2026-06-17.