CVE-2020-23774: Winmail Project Winmail

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be executed.

Affected products

Published 2021-01-26. Last modified 2026-06-17.