CVE-2020-23774: Winmail Project Winmail
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be executed.
Affected products
- Winmail Project Winmail: version 6.5 only
Published 2021-01-26. Last modified 2026-06-17.