SuperWebMailer Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for SuperWebMailer products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

0

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

SuperWebMailer KEVs Added by Year

Loading...

2 SuperWebMailer KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-11546

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An...

High Not in CISA 08 Jun 2025
CVE-2023-38192

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.

High Not in CISA 21 Oct 2023

Common Vulnerability Classes (CWE)

  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology