🔐 CVE Alert

CVE-2026-23610

MEDIUM 5.4

GFI MailEssentials AI < 22.4 POP2Exchange POP3 Server Login Stored XSS

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange configuration endpoint. An authenticated user can supply HTML/JavaScript in the POP3 server login field within the JSON \"popServers\" payload to /MailEssentials/pages/MailSecurity/POP2Exchange.aspx/Save, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.

CWE CWE-79
Vendor gfi software
Product mailessentials ai
Published Feb 19, 2026
Last Updated Mar 2, 2026
Stay Ahead of the Next One

Get instant alerts for gfi software mailessentials ai

Be the first to know when new medium vulnerabilities affecting gfi software mailessentials ai are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

GFI Software / MailEssentials AI
0 < 22.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
gfi.ai: https://gfi.ai/products-and-solutions/network-security-solutions/mailessentials/resources/documentation/product-releases vulncheck.com: https://www.vulncheck.com/advisories/gfi-mailessentials-ai-pop2exchange-pop3-server-login-stored-xss

Credits

Alex Williams from Pellera Technologies VulnCheck