Mailwise
14 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Mailwise, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
Mailwise CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium11
- Low1
Latest CVEs
The 14 most recently published vulnerabilities affecting Mailwise.
- CVE-2020-5572Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the product via unspecified vectors.4.6
- CVE-2018-0702Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.7.5
- CVE-2018-0558Reflected cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML in 'System settings' via unspecified vectors.6.1
- CVE-2018-0557Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'E-mail Details Screen' via unspecified vectors.6.1
- CVE-2018-0559Cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'Address' via unspecified vectors.6.1
- CVE-2016-4841Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.4.3
- CVE-2016-4844Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.4.3
- CVE-2016-4842Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.4.3
- CVE-2016-4843Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.6.5
- CVE-2014-5314Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to execute arbitrary code via e-mail messages.9.0
- CVE-2013-4698Cybozu Mailwise 5.0.4 and 5.0.5 allows remote authenticated users to obtain sensitive e-mail content intended for different persons in opportunistic circumstances by reading Subject header lines wi...3.5
- CVE-2013-2305Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the...6.8
- CVE-2011-1334Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise before 3.1, and Cybozu Collaborex before 1.5 allows remote a...4.3
- CVE-2006-4491Directory traversal vulnerability in Cybozu Collaborex, AG before 1.2(1.5), AG Pocket before 5.2(0.8), Mailwise before 3.0(0.3), and Garoon 1 before 1.5(4.1) allows remote authenticated users to re...4.0
Product grouping is registry-driven, with AI assist and human review. How it works