Afterlogic

    Dashboard / Vendors

    Products: 8
    Vulnerabilities: 13
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-12460

    Stored XSS vulnerability in Afterlogic Aurora webmail

    Last Modified: Apr 15, 2026
    Published: Oct 31, 2025

    CVE-2023-43176

    A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

    Last Modified: Nov 21, 2024
    Published: Oct 03, 2023

    CVE-2021-26294

    An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2021

    CVE-2021-26293

    An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

    Last Modified: Nov 21, 2024
    Published: Mar 04, 2021

    CVE-2019-19129

    Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.

    Last Modified: Nov 21, 2024
    Published: Nov 26, 2019
    Items Per Page