CVE-2025-3929: MDaemon Email Server
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
Affected products
- MDaemon Email Server: from 20.0.0, before 20.0.9 (fixed in 20.0.9); from 21.0.0, before 21.0.8 (fixed in 21.0.8); from 21.5.0, before 21.5.6 (fixed in 21.5.6); from 22.0.0, before 22.0.7 (fixed in 22.0.7); from 23.0.0, before 23.0.4 (fixed in 23.0.4); from 23.5.0, before 23.5.5 (fixed in 23.5.5); …
Published 2025-04-29. Last modified 2026-06-17.