VendorsBulwarkmailwebmailany version
Vulnerabilities

Bulwarkmail Webmail any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-34834
Bulwark Webmail: Authentication Bypass in verifyIdentity() due to missing cookie validation
Published 2026-04-02 · Analyzed
8.7EPSS 0.004
CVE-2026-34833
Bulwark Webmail: Information Exposure: password returned in /api/auth/session
Published 2026-04-02 · Analyzed
8.7EPSS 0.003
CVE-2026-35389
Bulwark Webmail S/MIME signature verification accepted self-signed certificates
Published 2026-04-06 · Analyzed
8.7EPSS 0.002
CVE-2026-35391
Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery
Published 2026-04-06 · Analyzed
8.7EPSS 0.002
CVE-2026-35390
Content-Security-Policy was set to Report-Only mode, failing to block XSS attacks
Published 2026-04-06 · Analyzed
6.1EPSS 0.002