๐Ÿ” CVE Alert

CVE-2026-48534

MEDIUM 5.4

GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the IMAP Server configuration page.

CWE CWE-79
Vendor gfi software
Product gfi archiver
Published Jul 23, 2026
Last Updated Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for gfi software gfi archiver

Be the first to know when new medium vulnerabilities affecting gfi software gfi archiver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

GFI Software / GFI Archiver
0 < 15.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gfi.ai: https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases vulncheck.com: https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-imapserverwizard-aspx

Credits

Alex Williams from Pellera Technologies VulnCheck