Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
Loading...
Loading...
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
September 5, 2002
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
GNU Mailman 2.0.x - Admin Login Variant Cross-Site Scripting
Open source ↗GNU Mailman 2.0.x - Subscribe Cross-Site Scripting
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2002-0855
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.