<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — MDaemon</title><description>Actively exploited vulnerabilities affecting MDaemon products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/mdaemon.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2024-11182 — MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-11182</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-11182</guid><description>MDaemon Email Server contains a cross-site scripting flaw that lets a remote attacker embed and execute arbitrary JavaScript in a victim&apos;s browser simply by sending a crafted HTML email. Because email is a universal attack vector requiring no special access, this vulnerability has a broad potential impact — any user who opens a malicious message could have their session hijacked, credentials stolen, or browser actions manipulated without any further interaction from the attacker.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>MDaemon</category><category>Email Server</category></item></channel></rss>