VendorsGFIkerio_connectall versions
Vulnerabilities

GFI Kerio Connect

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-25267
An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). There is a stack-based Buffer Overflow in the webmail component's 2FASetup function via an authenticated request with a long primaryEMailAddress field to the webmail/api/jsonrpc URI.
Published 2023-03-15 · Modified
8.8EPSS 0.010
CVE-2017-7440
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
Published 2017-05-02 · Modified
6.5EPSS 0.009
CVE-2025-2975
GFI KerioConnect Signature EditHtmlSource cross site scripting
Published 2025-03-31 · Analyzed
5.4EPSS 0.003
CVE-2025-2977
GFI KerioConnect PDF File cross site scripting
Published 2025-03-31 · Analyzed
5.4EPSS 0.003
CVE-2025-2976
GFI KerioConnect File Upload cross site scripting
Published 2025-03-31 · Analyzed
5.4EPSS 0.003