GFI
GFI Archiver: vulnerabilidades y CVE
GFI Archiver tiene 17 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses13
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48539 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report… |
| CVE-2026-48538 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured… |
| CVE-2026-48537 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded… |
| CVE-2026-48536 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server… |
| CVE-2026-48535 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server… |
| CVE-2026-48534 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to… |
| CVE-2026-48532 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy… |
| CVE-2026-48531 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name… |
| CVE-2026-48530 | Media (5.1) | 0.24% | — | 23 jul 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and… |
| CVE-2026-2039 | Crítica (9.8) | 0.69% | — | 20 feb 2026 | GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not… |
| CVE-2026-2038 | Crítica (9.8) | 0.66% | — | 20 feb 2026 | GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not… |
| CVE-2026-2037 | Alta (8.8) | 1.2% | — | 20 feb 2026 | GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although… |
| CVE-2026-2036 | Alta (8.8) | 1.2% | — | 20 feb 2026 | GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although… |
| CVE-2024-11949 | Alta (8.8) | 0.79% | — | 12 dic 2024 | GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver.… |
| CVE-2024-11948 | Crítica (9.8) | 1.4% | — | 12 dic 2024 | GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit… |
| CVE-2024-11947 | Alta (8.8) | 0.79% | — | 12 dic 2024 | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver.… |
| CVE-2021-29281 | Crítica (9.8) | 2.6% | — | 7 jul 2022 | File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.