CVE-2025-34490: Gfi Mailessentials
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Affected products
- Gfi Mailessentials: before 21.8 (fixed in 21.8)
Published 2025-04-28. Last modified 2026-06-17.