🔐 CVE Alert

CVE-2026-23613

MEDIUM 5.4

GFI MailEssentials AI < 22.4 Anti-Spam URI DNS Blocklist Domain Stored XSS

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the URI DNS Blocklist configuration page. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_URIs parameter to /MailEssentials/pages/MailSecurity/uridnsblocklist.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.

CWE CWE-79
Vendor gfi software
Product mailessentials ai
Published Feb 19, 2026
Last Updated Mar 2, 2026
Stay Ahead of the Next One

Get instant alerts for gfi software mailessentials ai

Be the first to know when new medium vulnerabilities affecting gfi software mailessentials ai are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

GFI Software / MailEssentials AI
0 < 22.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
gfi.ai: https://gfi.ai/products-and-solutions/network-security-solutions/mailessentials/resources/documentation/product-releases vulncheck.com: https://www.vulncheck.com/advisories/gfi-mailessentials-ai-anti-spam-uri-dns-blocklist-domain-stored-xss

Credits

Alex Williams from Pellera Technologies VulnCheck