Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

GFI MailEssentials Stored XSS Vulnerability in Email Exceptions Interface

CVE-2026-23615
Summary

GFI MailEssentials versions prior to 22.4 have a security issue that allows an authenticated user to execute malicious scripts when accessing the Email Exceptions interface. This could potentially lead to unauthorized actions being taken within the system. To fix this, update to version 22.4 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
gfi mailessentials <= 22.4
Original title
GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface. An authenticated user can supply HTML/Jav...
Original description
GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv4$txtEmailDescription parameter to /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.
nvd CVSS3.1 5.4
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026