CVE-2025-68643

Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the timeFormat preference by exploiting a separate vulnerability or using compromised credentials. In the second stage, when the victim logs into the WebMail interface, the unsanitized timeFormat value is loaded from storage and inserted into the DOM, causing the injected script to execute.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*:*
cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*:*

History

10 Feb 2026, 14:45

Type Values Removed Values Added
References () https://www.axigen.com/knowledgebase/Axigen-WebMail-Stored-XSS-Vulnerability-CVE-2025-68643-_405.html - () https://www.axigen.com/knowledgebase/Axigen-WebMail-Stored-XSS-Vulnerability-CVE-2025-68643-_405.html - Vendor Advisory
References () https://www.axigen.com/mail-server/download/ - () https://www.axigen.com/mail-server/download/ - Product
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*:*
First Time Axigen axigen Mail Server
Axigen

09 Feb 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

05 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-05 17:16

Updated : 2026-02-11 21:16


NVD link : CVE-2025-68643

Mitre link : CVE-2025-68643

CVE.ORG link : CVE-2025-68643


JSON object : View

Products Affected

axigen

  • axigen_mail_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')