Every CVE whose affected-product data names Axllent Mailpit, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (10)
CVE-2026-45713 — CVSS 7.5 (high): Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field…
CVE-2026-22689 — CVSS 6.5 (medium): Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept…
CVE-2026-45711 — CVSS 5.9 (medium): Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command…
CVE-2026-45712 — CVSS 5.9 (medium): Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a…
CVE-2026-21859 — CVSS 5.8 (medium): Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability…
CVE-2026-23845 — CVSS 5.8 (medium): Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via…
CVE-2026-27808 — CVSS 5.8 (medium): Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{ID}/link-check) is…
CVE-2026-45709 — CVSS 5.8 (medium): Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery…
CVE-2026-23829 — CVSS 5.3 (medium): Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection…
CVE-2026-48824 — CVSS 5.3 (medium): Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710…