Stored Cross-Site Scripting Vulnerability in GFI MailEssentials AI
CVE-2026-23612

5.1MEDIUM

Key Information:

Vendor
CVE Published:
19 February 2026

What is CVE-2026-23612?

GFI MailEssentials AI versions before 22.4 are vulnerable to a stored cross-site scripting issue via the IP DNS Blocklist configuration page. This vulnerability allows an authenticated user to inject malicious HTML/JavaScript code through the IP address input parameter in the management interface. The injected script is stored and executed later when the page is rendered, potentially compromising the security of logged-in users. It is crucial for users to upgrade to the latest version to mitigate this risk.

Affected Version(s)

MailEssentials AI 0 < 22.4

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.